GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,722
Erlang
35
GitHub Actions
29
Go
2,306
Maven
5,000+
npm
3,947
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,400 advisories
Filter by severity
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
High
CVE-2025-48383
was published
for
django-select2
(pip)
May 27, 2025
Strapi allows Server-Side Request Forgery in Webhook function
Moderate
CVE-2024-52588
was published
for
@strapi/admin
(npm)
May 27, 2025
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-5186
was published
May 26, 2025
A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System...
Moderate
Unreviewed
CVE-2025-5140
was published
May 25, 2025
A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3...
Moderate
Unreviewed
CVE-2025-48739
was published
May 23, 2025
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials...
High
Unreviewed
CVE-2024-13957
was published
May 22, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this...
Critical
Unreviewed
CVE-2025-36560
was published
May 19, 2025
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
High
Unreviewed
CVE-2025-40595
was published
May 14, 2025
The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Moderate
Unreviewed
CVE-2024-13940
was published
May 14, 2025
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
Critical
Unreviewed
CVE-2025-45887
was published
May 9, 2025
Server-Side Request Forgery (SSRF) in Azure allows an authorized attacker to perform spoofing...
Critical
Unreviewed
CVE-2025-29972
was published
May 9, 2025
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2025-47733
was published
May 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request...
Moderate
Unreviewed
CVE-2025-47664
was published
May 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows Server...
Moderate
Unreviewed
CVE-2025-47635
was published
May 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link...
Moderate
Unreviewed
CVE-2025-47548
was published
May 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block...
Moderate
Unreviewed
CVE-2025-47484
was published
May 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in Iulia Cazan Easy Replace Image allows Server...
Moderate
Unreviewed
CVE-2025-47483
was published
May 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra allows Server Side...
Moderate
Unreviewed
CVE-2025-47464
was published
May 7, 2025
MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url...
Moderate
Unreviewed
CVE-2025-45250
was published
May 6, 2025
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
High
Unreviewed
CVE-2024-48907
was published
May 2, 2025
IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF)....
Moderate
Unreviewed
CVE-2024-55910
was published
May 2, 2025
The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in...
Moderate
Unreviewed
CVE-2024-13845
was published
May 1, 2025
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
High
Unreviewed
CVE-2025-2170
was published
Apr 30, 2025
DevExpress before 23.1.3 allows AsyncDownloader SSRF.
Moderate
Unreviewed
CVE-2023-35817
was published
Apr 28, 2025
ProTip!
Advisories are also available from the
GraphQL API