GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,250 advisories
Filter by severity
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin...
Moderate
Unreviewed
CVE-2026-84663
was published
Sep 2, 2026
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093...
High
Unreviewed
CVE-2026-84649
was published
Sep 2, 2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF...
Moderate
Unreviewed
CVE-2026-8151
was published
Sep 2, 2026
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
Moderate
CVE-2026-81890
was published
for
studio-42/elfinder
(Composer)
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
High
Unreviewed
CVE-2026-84770
was published
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
High
Unreviewed
CVE-2026-84759
was published
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23...
High
Unreviewed
CVE-2026-84764
was published
Sep 2, 2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site...
Moderate
Unreviewed
CVE-2026-66652
was published
Sep 2, 2026
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its...
Moderate
Unreviewed
CVE-2026-81426
was published
Sep 2, 2026
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on...
Moderate
Unreviewed
CVE-2026-81432
was published
Sep 2, 2026
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to...
High
Unreviewed
CVE-2026-73780
was published
Sep 1, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
High
Unreviewed
CVE-2026-73718
was published
Sep 1, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co....
High
Unreviewed
CVE-2026-18780
was published
Sep 1, 2026
AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows...
High
Unreviewed
CVE-2026-83595
was published
Sep 1, 2026
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
Moderate
CVE-2026-81888
was published
for
@hono/oauth-providers
(npm)
Aug 31, 2026
ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request...
Moderate
Unreviewed
CVE-2026-71378
was published
Aug 31, 2026
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows...
Moderate
Unreviewed
CVE-2026-82647
was published
Aug 30, 2026
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function...
Moderate
Unreviewed
CVE-2026-82544
was published
Aug 30, 2026
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in...
Moderate
Unreviewed
CVE-2026-82468
was published
Aug 29, 2026
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when...
Moderate
Unreviewed
CVE-2026-17522
was published
Aug 29, 2026
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery...
Moderate
Unreviewed
CVE-2026-81733
was published
Aug 28, 2026
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF...
High
Unreviewed
CVE-2026-78610
was published
Aug 28, 2026
The Ebyte device does not adequately verify the origin or authenticity of
requests submitted to...
High
Unreviewed
CVE-2026-75814
was published
Aug 28, 2026
FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls...
High
Unreviewed
CVE-2026-80210
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API