GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,417
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
354 advisories
Filter by severity
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux ...
High
Unreviewed
CVE-2025-52453
was published
Jul 25, 2025
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php...
High
Unreviewed
CVE-2025-36845
was published
Jul 21, 2025
CWE-918 Server-Side Request Forgery (SSRF)
High
Unreviewed
CVE-2025-46385
was published
Jul 20, 2025
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy...
High
Unreviewed
CVE-2024-43204
was published
Jul 10, 2025
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak...
High
Unreviewed
CVE-2024-43394
was published
Jul 10, 2025
In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability...
High
Unreviewed
CVE-2024-11031
was published
Mar 20, 2025
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2025-6851
was published
Jul 11, 2025
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in...
High
Unreviewed
CVE-2025-21384
was published
Apr 1, 2025
Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allows Server Side...
High
Unreviewed
CVE-2025-49418
was published
Jul 4, 2025
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request...
High
Unreviewed
CVE-2025-5817
was published
Jul 2, 2025
SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious...
High
Unreviewed
CVE-2024-38472
was published
Jul 1, 2024
The CloudStack management server and secondary storage VM could be tricked into making requests...
High
Unreviewed
CVE-2024-29007
was published
Apr 4, 2024
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a Server-Side...
High
Unreviewed
CVE-2025-49852
was published
Jun 24, 2025
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-2940
was published
Jun 27, 2025
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending...
High
Unreviewed
CVE-2025-23172
was published
Jun 19, 2025
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central...
High
Unreviewed
CVE-2023-52331
was published
Jan 23, 2024
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow...
High
Unreviewed
CVE-2025-30680
was published
Jun 17, 2025
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component ...
High
Unreviewed
CVE-2024-48360
was published
Oct 31, 2024
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
High
Unreviewed
CVE-2025-45474
was published
May 29, 2025
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials...
High
Unreviewed
CVE-2024-13957
was published
May 22, 2025
The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with...
High
Unreviewed
CVE-2024-4469
was published
May 31, 2024
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because...
High
Unreviewed
CVE-2023-6199
was published
Nov 21, 2023
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can...
High
Unreviewed
CVE-2024-42168
was published
Jan 11, 2025
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
High
Unreviewed
CVE-2025-40595
was published
May 14, 2025
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2024-1812
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API