GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,767
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,965
NuGet
713
pip
3,748
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,424 advisories
Filter by severity
GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx
High
GHSA-68cf-j696-wvv9
was published
for
org.geoserver:gs-wfs
(Maven)
Jun 10, 2025
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High
GHSA-2p76-gc46-5fvc
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Jun 10, 2025
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
High
CVE-2025-30220
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0...
Moderate
Unreviewed
CVE-2023-48786
was published
Jun 10, 2025
Coverage REST API Server Side Request Forgery
Moderate
CVE-2024-40625
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
High
CVE-2024-29198
was published
for
org.geoserver.web:gs-app
(Maven)
Jun 10, 2025
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Moderate
CVE-2025-27817
was published
for
org.apache.kafka:kafka-clients
(Maven)
Jun 10, 2025
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an...
Low
Unreviewed
CVE-2025-42988
was published
Jun 10, 2025
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services allows...
Moderate
Unreviewed
CVE-2025-30997
was published
Jun 6, 2025
Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks allows Server Side Request...
Moderate
Unreviewed
CVE-2025-30976
was published
Jun 6, 2025
Server-Side Request Forgery (SSRF) vulnerability in ShawonPro SocialMark allows Server Side...
Moderate
Unreviewed
CVE-2025-29008
was published
Jun 6, 2025
Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber...
Moderate
Unreviewed
CVE-2025-48962
was published
Jun 4, 2025
A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This...
Moderate
Unreviewed
CVE-2025-5510
was published
Jun 3, 2025
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to...
Moderate
Unreviewed
CVE-2024-7073
was published
Jun 2, 2025
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
Moderate
Unreviewed
CVE-2025-37090
was published
Jun 2, 2025
A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects...
Moderate
Unreviewed
CVE-2025-5327
was published
May 29, 2025
Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the...
Critical
Unreviewed
CVE-2025-4967
was published
May 29, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
High
Unreviewed
CVE-2025-45474
was published
May 29, 2025
Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Moderate
CVE-2025-5276
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link...
Moderate
Unreviewed
CVE-2025-45475
was published
May 27, 2025
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
High
CVE-2025-48383
was published
for
django-select2
(pip)
May 27, 2025
Strapi allows Server-Side Request Forgery in Webhook function
Moderate
CVE-2024-52588
was published
for
@strapi/admin
(npm)
May 27, 2025
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-5186
was published
May 26, 2025
A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System...
Moderate
Unreviewed
CVE-2025-5140
was published
May 25, 2025
ProTip!
Advisories are also available from the
GraphQL API