GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,370 advisories
Filter by severity
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross...
High
Unreviewed
CVE-2026-39718
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage...
High
Unreviewed
CVE-2026-104448
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page...
Moderate
Unreviewed
CVE-2026-104452
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that...
Moderate
Unreviewed
CVE-2026-104451
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action...
Moderate
Unreviewed
CVE-2026-104453
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate...
High
Unreviewed
CVE-2026-104447
was published
Oct 2, 2026
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API...
High
Unreviewed
CVE-2026-104059
was published
Oct 1, 2026
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin...
High
Unreviewed
CVE-2026-103067
was published
Oct 1, 2026
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in...
Low
Unreviewed
CVE-2026-94220
was published
Oct 1, 2026
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in...
Moderate
Unreviewed
CVE-2026-103285
was published
Oct 1, 2026
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager...
High
Unreviewed
CVE-2026-64947
was published
Oct 1, 2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands...
Moderate
Unreviewed
CVE-2026-34190
was published
Oct 1, 2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses...
Moderate
Unreviewed
CVE-2026-34189
was published
Oct 1, 2026
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU)...
High
Unreviewed
CVE-2026-101147
was published
Oct 1, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2...
Moderate
Unreviewed
CVE-2026-97299
was published
Sep 30, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti...
High
Unreviewed
CVE-2026-96838
was published
Sep 30, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Moderate
Unreviewed
CVE-2026-102399
was published
Sep 30, 2026
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site...
High
Unreviewed
CVE-2026-67993
was published
Sep 29, 2026
Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote...
High
Unreviewed
CVE-2026-95362
was published
Sep 29, 2026
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker...
Moderate
Unreviewed
CVE-2026-41875
was published
Sep 29, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross...
Moderate
Unreviewed
CVE-2026-73597
was published
Sep 29, 2026
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that...
Moderate
Unreviewed
CVE-2026-101093
was published
Sep 29, 2026
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a...
High
Unreviewed
CVE-2026-82380
was published
Sep 28, 2026
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to...
Low
Unreviewed
CVE-2026-100873
was published
Sep 27, 2026
ProTip!
Advisories are also available from the
GraphQL API