GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,612
Maven
5,000+
npm
4,252
NuGet
760
pip
4,027
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,161 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request...
Unknown
Unreviewed
CVE-2025-10930
was published
Oct 30, 2025
Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU...
Critical
Unreviewed
CVE-2025-12479
was published
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
Moderate
CVE-2025-64149
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507....
Moderate
Unreviewed
CVE-2024-45161
was published
Oct 29, 2025
Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64138
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64133
was published
for
jp.ikedam.jenkins.plugins:extensible-choice-parameter
(Maven)
Oct 29, 2025
Jenkins Themis Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64136
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64141
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for...
Moderate
Unreviewed
CVE-2025-64290
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross...
Moderate
Unreviewed
CVE-2025-64288
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross...
Moderate
Unreviewed
CVE-2025-64286
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in colabrio Stockie Extra stockie-extra allows...
Moderate
Unreviewed
CVE-2025-64226
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress...
Moderate
Unreviewed
CVE-2025-64201
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder...
Moderate
Unreviewed
CVE-2025-58939
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress...
High
Unreviewed
CVE-2025-60075
was published
Oct 29, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box allows Cross Site Request...
Moderate
Unreviewed
CVE-2025-57931
was published
Oct 29, 2025
Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.
Moderate
Unreviewed
CVE-2025-55758
was published
Oct 28, 2025
Liferay Portal Vulnerable to CSRF in Headless APIs
High
CVE-2025-62258
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does...
Moderate
Unreviewed
CVE-2025-54969
was published
Oct 27, 2025
Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF)...
High
Unreviewed
CVE-2025-34133
was published
Oct 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Waituk Entrada theme allows Cross Site Request...
Moderate
Unreviewed
CVE-2025-58918
was published
Oct 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc...
High
Unreviewed
CVE-2025-62957
was published
Oct 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in iseremet Reloadly reloadly-topup-widget allows...
High
Unreviewed
CVE-2025-62956
was published
Oct 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for...
High
Unreviewed
CVE-2025-62958
was published
Oct 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search...
High
Unreviewed
CVE-2025-62962
was published
Oct 27, 2025
ProTip!
Advisories are also available from the
GraphQL API