GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
301 advisories
Filter by severity
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182
High
CVE-2023-50731
was published
for
mindsdb
(pip)
Dec 15, 2023
Server-Side Request Forgery in mindsdb
Moderate
CVE-2023-49795
was published
for
mindsdb
(pip)
Dec 12, 2023
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
Critical
CVE-2023-48910
was published
for
io.github.microcks:microcks
(Maven)
Dec 4, 2023
google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
Low
CVE-2023-48711
was published
for
google-translate-api-browser
(npm)
Nov 27, 2023
Cookies are sent to external images in rendered diff (and server side request forgery)
Critical
CVE-2023-48240
was published
for
org.xwiki.platform:xwiki-platform-diff-xml
(Maven)
Nov 20, 2023
Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
Moderate
CVE-2023-46729
was published
for
@sentry/nextjs
(npm)
Nov 9, 2023
FoodCoopShop Server-Side Request Forgery vulnerability
High
CVE-2023-46725
was published
for
foodcoopshop/foodcoopshop
(Composer)
Nov 2, 2023
OpenCRX allows a remote attacker to execute arbitrary code via a crafted request
Critical
CVE-2023-46502
was published
for
org.opencrx:opencrx-client
(Maven)
Oct 31, 2023
WPS Server Side Request Forgery vulnerability
High
CVE-2023-43795
was published
for
org.geoserver.extension:gs-wps-core
(Maven)
Oct 24, 2023
Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF
Moderate
CVE-2023-41339
was published
for
org.geoserver.web:gs-web-app
(Maven)
Oct 24, 2023
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
High
CVE-2023-46124
was published
for
ethyca-fides
(pip)
Oct 24, 2023
Langchain Server-Side Request Forgery vulnerability
High
CVE-2023-32786
was published
for
langchain
(pip)
Oct 21, 2023
Artifact Hub allows unsafe rego built-in
Low
CVE-2023-45822
was published
for
github.com/artifacthub/hub
(Go)
Oct 19, 2023
Apache Shenyu Server Side Request Forgery vulnerability
Moderate
CVE-2023-25753
was published
for
org.apache.shenyu:shenyu-admin
(Maven)
Oct 19, 2023
LangChain Server Side Request Forgery vulnerability
High
CVE-2023-46229
was published
for
langchain
(pip)
Oct 19, 2023
Server-Side Request Forgery (SSRF) in vriteio/vrite
Critical
CVE-2023-5572
was published
for
@vrite/sdk
(npm)
Oct 13, 2023
Presto JDBC Server-Side Request Forgery by nextUri
High
GHSA-86q5-qcjc-7pv4
was published
for
com.facebook.presto:presto-jdbc
(Maven)
Oct 3, 2023
Presto JDBC Server-Side Request Forgery by redirect
High
GHSA-xm7x-f3w2-4hjm
was published
for
com.facebook.presto:presto-jdbc
(Maven)
Oct 3, 2023
TorchServe Server-Side Request Forgery vulnerability
Critical
CVE-2023-43654
was published
for
torchserve
(pip)
Oct 2, 2023
GeoNode vulnerable to SSRF Bypass to return internal host data
High
CVE-2023-42439
was published
for
GeoNode
(pip)
Sep 20, 2023
WireMock Controlled Server Side Request Forgery vulnerability through URL
Moderate
CVE-2023-41327
was published
for
org.wiremock:wiremock-webhooks-extension
(Maven)
Sep 6, 2023
SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials
High
CVE-2023-41937
was published
for
io.jenkins.plugins:bitbucket-push-and-pull-request
(Maven)
Sep 6, 2023
Apache Superset has improper default REST API permission for Gamma users
Moderate
CVE-2023-36387
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Moderate
CVE-2023-36388
was published
for
apache-superset
(pip)
Sep 6, 2023
ProTip!
Advisories are also available from the
GraphQL API