GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,538 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link...
High
Unreviewed
CVE-2025-67465
was published
Dec 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact...
High
Unreviewed
CVE-2025-67471
was published
Dec 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Jacques Malgrange Rencontre rencontre allows...
High
Unreviewed
CVE-2025-67534
was published
Dec 9, 2025
Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote...
High
Unreviewed
CVE-2025-65573
was published
Dec 9, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality
High
CVE-2025-34410
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality
High
CVE-2025-34429
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability...
High
Unreviewed
CVE-2020-36900
was published
Dec 10, 2025
UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that...
High
Unreviewed
CVE-2020-36901
was published
Dec 10, 2025
A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8...
High
Unreviewed
CVE-2025-65472
was published
Dec 11, 2025
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack
due to the absence of...
High
Unreviewed
CVE-2025-13970
was published
Dec 13, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks...
High
Unreviewed
CVE-2025-65593
was published
Dec 16, 2025
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents...
High
Unreviewed
CVE-2025-65203
was published
Dec 17, 2025
CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker...
High
Unreviewed
CVE-2025-66953
was published
Dec 17, 2025
ProTip!
Advisories are also available from the
GraphQL API