GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
362 advisories
Filter by severity
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18...
High
Unreviewed
CVE-2025-6454
was published
Sep 12, 2025
Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server...
High
Unreviewed
CVE-2025-49430
was published
Sep 9, 2025
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for...
High
Unreviewed
CVE-2025-7813
was published
Aug 23, 2025
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
High
Unreviewed
CVE-2025-54924
was published
Aug 20, 2025
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
High
Unreviewed
CVE-2025-54925
was published
Aug 20, 2025
Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online...
High
Unreviewed
CVE-2025-5260
was published
Aug 20, 2025
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker...
High
Unreviewed
CVE-2025-53760
was published
Aug 12, 2025
Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32...
High
Unreviewed
CVE-2025-25235
was published
Aug 12, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux ...
High
Unreviewed
CVE-2025-52453
was published
Jul 25, 2025
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php...
High
Unreviewed
CVE-2025-36845
was published
Jul 21, 2025
CWE-918 Server-Side Request Forgery (SSRF)
High
Unreviewed
CVE-2025-46385
was published
Jul 20, 2025
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2025-6851
was published
Jul 11, 2025
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy...
High
Unreviewed
CVE-2024-43204
was published
Jul 10, 2025
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak...
High
Unreviewed
CVE-2024-43394
was published
Jul 10, 2025
Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allows Server Side...
High
Unreviewed
CVE-2025-49418
was published
Jul 4, 2025
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request...
High
Unreviewed
CVE-2025-5817
was published
Jul 2, 2025
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-2940
was published
Jun 27, 2025
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a Server-Side...
High
Unreviewed
CVE-2025-49852
was published
Jun 24, 2025
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending...
High
Unreviewed
CVE-2025-23172
was published
Jun 19, 2025
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow...
High
Unreviewed
CVE-2025-30680
was published
Jun 17, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
High
Unreviewed
CVE-2025-45474
was published
May 29, 2025
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials...
High
Unreviewed
CVE-2024-13957
was published
May 22, 2025
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
High
Unreviewed
CVE-2025-40595
was published
May 14, 2025
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
High
Unreviewed
CVE-2024-48907
was published
May 2, 2025
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
High
Unreviewed
CVE-2025-2170
was published
Apr 30, 2025
ProTip!
Advisories are also available from the
GraphQL API