Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9,260 advisories

Loading
Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/... Moderate Unreviewed
CVE-2026-82911 was published Sep 4, 2026
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) High
CVE-2026-73222 was published for claude-code-templates (npm) Sep 3, 2026
spartan8806 Credited to spartan8806
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation High
CVE-2026-73292 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
CamilleGR Credited to CamilleGR
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in... Moderate Unreviewed
CVE-2026-85161 was published Sep 3, 2026
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections Moderate
CVE-2026-81890 was published for studio-42/elfinder (Composer) Sep 2, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
TYPO3 CMS - Broken Access Control in Backend and Install Tool High
CVE-2026-19418 was published for typo3/cms-backend (Composer) Sep 1, 2026
ProTip! Advisories are also available from the GraphQL API