GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
344 advisories
Filter by severity
Cross-Site Request Forgery in JFinalCMS via admin/nav/delete
High
CVE-2023-49448
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/category/delete
High
CVE-2023-49398
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/tag/save
High
CVE-2023-49383
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/div/delete
High
CVE-2023-49382
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/nav/update
High
CVE-2023-49447
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/category/save
High
CVE-2023-49396
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/category/updateStatus
High
CVE-2023-49397
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/friend_link/update
High
CVE-2023-49375
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS
High
CVE-2023-49376
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via the component /admin/friend_link/save
High
CVE-2023-49379
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS
High
CVE-2023-49372
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/form/save
High
CVE-2023-49378
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/tag/update
High
CVE-2023-49377
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/friend_link/delete
High
CVE-2023-49380
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS
High
CVE-2023-49373
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Cross-Site Request Forgery in JFinalCMS via /admin/slide/update
High
CVE-2023-49374
was published
for
com.jfinal:jfinal
(Maven)
Dec 5, 2023
Jenkins MATLAB Plugin cross-site request forgery vulnerability
High
CVE-2023-49655
was published
for
org.jenkins-ci.plugins:matlab
(Maven)
Nov 29, 2023
Cross Site Request Forgery in SwiftyEdit
High
CVE-2023-47350
was published
for
swiftyedit/swiftyedit
(Composer)
Nov 22, 2023
Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries
High
CVE-2023-48293
was published
for
org.xwiki.contrib:xwiki-application-admintools
(Maven)
Nov 20, 2023
Cross-Site Request Forgery vulnerability in Prefect
High
CVE-2023-6022
was published
for
prefect
(pip)
Nov 16, 2023
Go Fiber CSRF Token Validation Vulnerability
High
CVE-2023-45141
was published
for
github.com/gofiber/fiber/v2
(Go)
Oct 17, 2023
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
High
CVE-2023-5511
was published
for
snipe/snipe-it
(Composer)
Oct 11, 2023
Cross-Site Request Forgery (CSRF) in usememos/memos
High
CVE-2023-5036
was published
for
github.com/usememos/memos
(Go)
Sep 18, 2023
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
High
CVE-2023-40572
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Aug 23, 2023
Jenkins Folders Plugin cross-site request forgery vulnerability
High
CVE-2023-40336
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
ProTip!
Advisories are also available from the
GraphQL API