GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
562 advisories
Filter by severity
A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4...
Moderate
Unreviewed
CVE-2025-8772
was published
Aug 9, 2025
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0...
Moderate
Unreviewed
CVE-2025-4581
was published
Aug 9, 2025
Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in...
Moderate
Unreviewed
CVE-2025-51058
was published
Aug 6, 2025
4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery ...
Moderate
Unreviewed
CVE-2024-55399
was published
Aug 6, 2025
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers...
Moderate
Unreviewed
CVE-2025-50234
was published
Aug 6, 2025
A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0....
Moderate
Unreviewed
CVE-2025-8529
was published
Aug 5, 2025
A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue...
Moderate
Unreviewed
CVE-2025-8527
was published
Aug 5, 2025
A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability...
Moderate
Unreviewed
CVE-2025-8520
was published
Aug 4, 2025
A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream...
Moderate
Unreviewed
CVE-2025-24485
was published
Jul 28, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-8228
was published
Jul 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux ...
Moderate
Unreviewed
CVE-2025-52454
was published
Jul 25, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux ...
Moderate
Unreviewed
CVE-2025-52455
was published
Jul 25, 2025
Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook...
Moderate
Unreviewed
CVE-2025-45939
was published
Jul 25, 2025
A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This...
Moderate
Unreviewed
CVE-2025-8133
was published
Jul 25, 2025
The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-5818
was published
Jul 23, 2025
A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH...
Moderate
Unreviewed
CVE-2025-52163
was published
Jul 18, 2025
A vulnerability, which was classified as critical, was found in thinkgem JeeSite up to 5.12.0....
Moderate
Unreviewed
CVE-2025-7759
was published
Jul 18, 2025
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could...
Moderate
Unreviewed
CVE-2025-20288
was published
Jul 16, 2025
Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server...
Moderate
Unreviewed
CVE-2025-48294
was published
Jul 16, 2025
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and...
Moderate
Unreviewed
CVE-2025-51591
was published
Jul 11, 2025
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated...
Moderate
Unreviewed
CVE-2025-50125
was published
Jul 11, 2025
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request...
Moderate
Unreviewed
CVE-2025-49545
was published
Jul 8, 2025
SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22...
Moderate
Unreviewed
CVE-2025-0292
was published
Jul 8, 2025
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network...
Moderate
Unreviewed
CVE-2025-42965
was published
Jul 8, 2025
Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and...
Moderate
Unreviewed
CVE-2025-53473
was published
Jul 7, 2025
ProTip!
Advisories are also available from the
GraphQL API