GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,478
Erlang
33
GitHub Actions
24
Go
2,208
Maven
5,000+
npm
3,865
NuGet
696
pip
3,642
Pub
12
RubyGems
913
Rust
919
Swift
38
Unreviewed advisories
All unreviewed
5,000+
244 advisories
Filter by severity
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
Critical
Unreviewed
CVE-2025-28091
was published
Mar 29, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled...
Critical
Unreviewed
CVE-2025-28089
was published
Mar 29, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection...
Critical
Unreviewed
CVE-2025-28090
was published
Mar 29, 2025
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the...
Critical
Unreviewed
CVE-2024-48590
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API...
Critical
Unreviewed
CVE-2024-9309
was published
Mar 20, 2025
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component ...
Critical
Unreviewed
CVE-2025-25785
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27651
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27652
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27655
was published
Mar 5, 2025
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due...
Critical
Unreviewed
CVE-2024-54819
was published
Jan 7, 2025
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API...
Critical
Unreviewed
CVE-2024-10044
was published
Dec 30, 2024
http4k has a potential XXE (XML External Entity Injection) vulnerability
Critical
CVE-2024-55875
was published
for
org.http4k:http4k-format-xml
(Maven)
Dec 12, 2024
Adobe Document Service allows an attacker with administrator privileges to send a crafted request...
Critical
Unreviewed
CVE-2024-47578
was published
Dec 10, 2024
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability...
Critical
Unreviewed
CVE-2024-48874
was published
Dec 6, 2024
Oxide control plane software before 5 allows SSRF.
Critical
Unreviewed
CVE-2023-50913
was published
Dec 5, 2024
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3....
Critical
Unreviewed
CVE-2024-38645
was published
Nov 22, 2024
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection')...
Critical
Unreviewed
CVE-2024-47208
was published
Nov 18, 2024
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-51358
was published
Nov 6, 2024
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
Critical
CVE-2024-47883
was published
for
org.openrefine.dependencies:butterfly
(Maven)
Oct 24, 2024
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via...
Critical
Unreviewed
CVE-2024-47222
was published
Sep 23, 2024
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an...
Critical
Unreviewed
CVE-2024-44677
was published
Sep 10, 2024
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at ...
Critical
Unreviewed
CVE-2024-44721
was published
Sep 9, 2024
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in...
Critical
Unreviewed
CVE-2024-38109
was published
Aug 13, 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-41651
was published
Aug 12, 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7...
Critical
Unreviewed
CVE-2024-41570
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API