GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
9,260 advisories
Filter by severity
A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function...
Low
Unreviewed
CVE-2026-86182
was published
Sep 6, 2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request...
High
Unreviewed
CVE-2026-82712
was published
Sep 4, 2026
Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/...
Moderate
Unreviewed
CVE-2026-82911
was published
Sep 4, 2026
A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF...
Moderate
Unreviewed
CVE-2026-85547
was published
Sep 4, 2026
MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit...
High
Unreviewed
CVE-2026-85546
was published
Sep 4, 2026
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
High
CVE-2026-73222
was published
for
claude-code-templates
(npm)
Sep 3, 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
High
CVE-2026-73292
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP....
High
Unreviewed
CVE-2026-85236
was published
Sep 3, 2026
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin...
High
Unreviewed
CVE-2026-85162
was published
Sep 3, 2026
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in...
Moderate
Unreviewed
CVE-2026-85161
was published
Sep 3, 2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin...
Moderate
Unreviewed
CVE-2026-84663
was published
Sep 2, 2026
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093...
High
Unreviewed
CVE-2026-84649
was published
Sep 2, 2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF...
Moderate
Unreviewed
CVE-2026-8151
was published
Sep 2, 2026
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
Moderate
CVE-2026-81890
was published
for
studio-42/elfinder
(Composer)
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23...
High
Unreviewed
CVE-2026-84764
was published
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
High
Unreviewed
CVE-2026-84770
was published
Sep 2, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
High
Unreviewed
CVE-2026-84759
was published
Sep 2, 2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site...
Moderate
Unreviewed
CVE-2026-66652
was published
Sep 2, 2026
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its...
Moderate
Unreviewed
CVE-2026-81426
was published
Sep 2, 2026
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on...
Moderate
Unreviewed
CVE-2026-81432
was published
Sep 2, 2026
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to...
High
Unreviewed
CVE-2026-73780
was published
Sep 1, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
High
Unreviewed
CVE-2026-73718
was published
Sep 1, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co....
High
Unreviewed
CVE-2026-18780
was published
Sep 1, 2026
AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows...
High
Unreviewed
CVE-2026-83595
was published
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API