GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,360 advisories
Filter by severity
The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its...
Moderate
Unreviewed
CVE-2021-24780
was published
Dec 14, 2021
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation...
Moderate
Unreviewed
CVE-2021-24790
was published
Dec 14, 2021
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its...
Moderate
Unreviewed
CVE-2021-24784
was published
Dec 14, 2021
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery ...
Moderate
Unreviewed
CVE-2021-24795
was published
Dec 14, 2021
The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings,...
Moderate
Unreviewed
CVE-2021-24818
was published
Dec 14, 2021
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation...
Moderate
Unreviewed
CVE-2021-24836
was published
Dec 14, 2021
Cross-Site Request Forgery in kimai2
Moderate
CVE-2021-4033
was published
for
kevinpapst/kimai2
(Composer)
Dec 10, 2021
Cross Site Request Forgery in firefly-iii
Moderate
CVE-2021-4005
was published
for
grumpydictator/firefly-iii
(Composer)
Dec 10, 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4015
was published
for
grumpydictator/firefly-iii
(Composer)
Dec 6, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3993
was published
for
showdoc/showdoc
(Composer)
Dec 3, 2021
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk...
Moderate
Unreviewed
CVE-2021-24749
was published
Nov 30, 2021
The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and...
Moderate
Unreviewed
CVE-2021-24822
was published
Nov 30, 2021
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the...
Moderate
Unreviewed
CVE-2021-24703
was published
Nov 24, 2021
Cross-site Scripting in kimai2
Moderate
CVE-2021-3976
was published
for
kevinpapst/kimai2
(Composer)
Nov 23, 2021
Cross-site Scripting in kimai2
Moderate
CVE-2021-3963
was published
for
kevinpapst/kimai2
(Composer)
Nov 23, 2021
Cross-site Scripting in kimai2
Moderate
CVE-2021-3957
was published
for
kevinpapst/kimai2
(Composer)
Nov 23, 2021
The disqualify lead action may be executed without CSRF token check
Moderate
CVE-2021-39198
was published
for
oro/crm
(Composer)
Nov 19, 2021
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
Moderate
CVE-2021-41273
was published
for
pterodactyl/panel
(Composer)
Nov 18, 2021
twill is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3932
was published
for
area17/twill
(Composer)
Nov 15, 2021
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3931
was published
for
snipe/snipe-it
(Composer)
Nov 15, 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3921
was published
for
grumpydictator/firefly-iii
(Composer)
Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3775
was published
for
showdoc/showdoc
(Composer)
Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3683
was published
for
showdoc/showdoc
(Composer)
Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-3776
was published
for
showdoc/showdoc
(Composer)
Nov 15, 2021
Request injection in Spring Cloud Gateway
Moderate
CVE-2021-22051
was published
for
org.springframework.cloud:spring-cloud-gateway
(Maven)
Nov 10, 2021
ProTip!
Advisories are also available from the
GraphQL API