GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
43 advisories
Filter by severity
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value...
Low
Unreviewed
CVE-2025-59437
was published
Sep 16, 2025
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value...
Low
Unreviewed
CVE-2025-59436
was published
Sep 16, 2025
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
Mautic vulnerable to SSRF via webhook function
Low
CVE-2025-9821
was published
for
mautic/core
(Composer)
Sep 3, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request...
Low
Unreviewed
CVE-2025-54234
was published
Aug 18, 2025
The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery...
Low
Unreviewed
CVE-2025-8013
was published
Aug 15, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an...
Low
Unreviewed
CVE-2025-42988
was published
Jun 10, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.
Low
Unreviewed
CVE-2025-29446
was published
Apr 21, 2025
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may...
Low
Unreviewed
CVE-2025-2987
was published
Apr 22, 2025
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit...
Low
Unreviewed
CVE-2023-45705
was published
Mar 28, 2024
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center)...
Low
Unreviewed
CVE-2025-27430
was published
Mar 11, 2025
langchain Server-Side Request Forgery vulnerability
Low
CVE-2024-0243
was published
for
langchain
(pip)
Feb 26, 2024
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input...
Low
Unreviewed
CVE-2024-52606
was published
Feb 11, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to...
Low
Unreviewed
CVE-2023-6195
was published
Jan 31, 2025
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form &...
Low
Unreviewed
CVE-2024-13450
was published
Jan 25, 2025
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. ...
Low
Unreviewed
CVE-2024-42182
was published
Jan 23, 2025
QOS.CH logback-core Server-Side Request Forgery vulnerability
Low
CVE-2024-12801
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 19, 2024
Northern.tech Hosted Mender before 2024.07.11 allows SSRF.
Low
Unreviewed
CVE-2024-47190
was published
Nov 8, 2024
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and...
Low
Unreviewed
CVE-2024-45843
was published
Sep 26, 2024
Authenticated Blind SSRF in automad/automad
Low
CVE-2023-7037
was published
for
automad/automad
(Composer)
Dec 21, 2023
ProTip!
Advisories are also available from the
GraphQL API