GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,415 advisories
Filter by severity
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Image Upload
Moderate
CVE-2025-28092
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP allows...
Moderate
Unreviewed
CVE-2025-31076
was published
Mar 28, 2025
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for...
Moderate
Unreviewed
CVE-2025-22672
was published
Mar 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in XpeedStudio Metform allows Server Side...
Moderate
Unreviewed
CVE-2025-30914
was published
Mar 27, 2025
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic....
Moderate
Unreviewed
CVE-2025-2835
was published
Mar 27, 2025
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress...
High
Unreviewed
CVE-2025-1912
was published
Mar 26, 2025
The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Moderate
Unreviewed
CVE-2024-13411
was published
Mar 26, 2025
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-2109
was published
Mar 25, 2025
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5...
Moderate
Unreviewed
CVE-2024-10206
was published
Mar 25, 2025
A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5...
Moderate
Unreviewed
CVE-2024-10207
was published
Mar 25, 2025
nossrf Server-Side Request Forgery (SSRF)
High
CVE-2025-2691
was published
for
nossrf
(npm)
Mar 23, 2025
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-1970
was published
Mar 22, 2025
The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-13856
was published
Mar 22, 2025
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the...
Critical
Unreviewed
CVE-2024-48590
was published
Mar 20, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2024-13923
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of...
High
Unreviewed
CVE-2025-0454
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10...
Moderate
Unreviewed
CVE-2025-0184
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt...
Moderate
Unreviewed
CVE-2025-0188
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API...
Critical
Unreviewed
CVE-2024-9309
was published
Mar 20, 2025
composio Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-8952
was published
for
composio-core
(pip)
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna...
High
Unreviewed
CVE-2024-8099
was published
Mar 20, 2025
Open WebUI has SSRF in /openai/models
High
CVE-2024-7959
was published
for
open-webui
(pip)
Mar 20, 2025
comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF)...
High
Unreviewed
CVE-2024-12882
was published
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API