GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
190 advisories
Filter by severity
Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
Moderate
CVE-2025-64149
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64141
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Jenkins Themis Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64136
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64138
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64133
was published
for
jp.ikedam.jenkins.plugins:extensible-choice-parameter
(Maven)
Oct 29, 2025
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Moderate
CVE-2025-41254
was published
for
org.springframework:spring-websocket
(Maven)
Oct 16, 2025
Liferay Portal is vulnerable to CSRF through publication comments
Moderate
CVE-2025-62245
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 10, 2025
Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-43809
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 19, 2025
Liferay Portal CSRF Vulnerability via Endpoint Parameter
Moderate
CVE-2025-43745
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Jenkins Cadence vManager Plugin Vulnerable to Cross-Site Request Forgery
Moderate
CVE-2025-47886
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 14, 2025
Cross-Site Request Forgery in OpenNMS Horizon
Moderate
CVE-2021-25930
was published
for
org.opennms:opennms
(Maven)
May 25, 2021
Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin
Moderate
CVE-2022-45398
was published
for
org.zeroturnaround:cluster-stats
(Maven)
Nov 16, 2022
Jenkins Simple Queue Plugin Cross-Site Request Forgery (CSRF)
Moderate
CVE-2025-31723
was published
for
io.jenkins.plugins:simple-queue
(Maven)
Apr 2, 2025
Jenkins cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2025-27624
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Cross-Site Request Forgery in Apache Wicket
Moderate
CVE-2024-27439
was published
for
org.apache.wicket:wicket
(Maven)
Mar 19, 2024
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Jenkins docker-build-step Plugin Cross-Site Request Forgery vulnerability
Moderate
CVE-2024-2215
was published
for
org.jenkins-ci.plugins:docker-build-step
(Maven)
Mar 6, 2024
Jenkins NeuVector Vulnerability Scanner Plugin Cross-Site Request Forgery vulnerability
Moderate
CVE-2023-49673
was published
for
io.jenkins.plugins:neuvector-vulnerability-scanner
(Maven)
Nov 29, 2023
CSRF vulnerability in Jenkins Nomad Plugin allow SSRF
Moderate
CVE-2019-10292
was published
for
org.jenkins-ci.plugins:kmap-jenkins
(Maven)
May 13, 2022
Apache Zeppelin CSRF vulnerability in the Credentials page
Moderate
CVE-2021-28656
was published
for
org.apache.zeppelin:zeppelin-web
(Maven)
Apr 9, 2024
Jenkins Subversion Partial Release Manager Plugin vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-28158
was published
for
org.jenkins-ci.plugins:svn-partial-release-mgr
(Maven)
Mar 6, 2024
BlazeMeter Jenkins plugin vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-3825
was published
for
com.blazemeter.plugins:BlazeMeterJenkinsPlugin
(Maven)
Apr 17, 2024
Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3
Moderate
CVE-2017-12631
was published
for
org.apache.cxf.fediz:fediz-spring
(Maven)
Oct 18, 2018
XWiki Platform CSRF in the job scheduler
Moderate
CVE-2024-31985
was published
for
org.xwiki.platform:xwiki-platform-scheduler-ui
(Maven)
Apr 10, 2024
CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux
Moderate
CVE-2020-5397
was published
for
org.springframework:spring-webflux
(Maven)
Jan 21, 2020
ProTip!
Advisories are also available from the
GraphQL API