GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,123 advisories
Filter by severity
Server Side Request Forgery (SSRF) attack in Fedify
High
CVE-2024-39687
was published
for
@fedify/fedify
(npm)
Jul 5, 2024
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via...
Critical
Unreviewed
CVE-2024-29319
was published
Jul 5, 2024
ShopXO Server-Side Request Forgery Vulnerability
Moderate
CVE-2024-6524
was published
for
shopxo/shopxo
(Composer)
Jul 5, 2024
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream...
High
Unreviewed
CVE-2024-5736
was published
Jul 3, 2024
SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious...
High
Unreviewed
CVE-2024-38472
was published
Jul 1, 2024
External server-side request vulnerability in MESbook 20221021.03 version, which could allow a...
Critical
Unreviewed
CVE-2024-6424
was published
Jul 1, 2024
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This...
Moderate
Unreviewed
CVE-2023-50952
was published
Jun 30, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of...
High
Unreviewed
CVE-2024-5822
was published
Jun 27, 2024
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The...
High
Unreviewed
CVE-2024-5885
was published
Jun 27, 2024
Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter...
Moderate
Unreviewed
CVE-2024-37098
was published
Jun 26, 2024
The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was...
High
Unreviewed
CVE-2024-34581
was published
Jun 26, 2024
Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing ...
Moderate
Unreviewed
CVE-2024-34580
was published
Jun 26, 2024
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a...
Moderate
Unreviewed
CVE-2024-29173
was published
Jun 26, 2024
In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability...
High
Unreviewed
CVE-2024-5014
was published
Jun 25, 2024
In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI...
High
Unreviewed
CVE-2024-5015
was published
Jun 25, 2024
Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an...
Unknown
Unreviewed
CVE-2023-45195
was published
Jun 25, 2024
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2024-5746
was published
Jun 21, 2024
Strapi Server-Side Request Forgery (SSRF)
High
CVE-2024-37818
was published
for
@strapi/strapi
(npm)
Jun 20, 2024
Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-34111
was published
for
magento/community-edition
(Composer)
Jun 13, 2024
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side...
Moderate
Unreviewed
CVE-2024-4354
was published
Jun 7, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex...
Critical
Unreviewed
CVE-2024-3149
was published
Jun 6, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez...
High
Unreviewed
CVE-2024-5186
was published
Jun 6, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application,...
High
Unreviewed
CVE-2024-4851
was published
Jun 6, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application,...
High
Unreviewed
CVE-2024-5328
was published
Jun 6, 2024
ProTip!
Advisories are also available from the
GraphQL API