GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            797 advisories
        Filter by severity
        
      
      
    
                    
                      A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43747
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-39954
                      
                      was published
                        for
                        
                          org.apache.eventmesh:eventmesh-runtime
                        
                        (Maven)
                      Aug 20, 2025 
                    
                  
                    
                      Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-52602
                      
                      was published
                        for
                        
                          github.com/t2bot/matrix-media-repo
                        
                        (Go)
                      Jan 16, 2025 
                    
                  
                    
                      IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-1142
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      WP Crontrol Authenticated (Administrator+) plugin vulnerable to Blind Server-Side Request Forgery
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8678
                      
                      was published
                        for
                        
                          johnbillion/wp-crontrol
                        
                        (Composer)
                      Aug 19, 2025 
                    
                  
                    
                      Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8675
                      
                      was published
                      Aug 15, 2025 
                    
                  
                    
                      The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8680
                      
                      was published
                      Aug 15, 2025 
                    
                  
                    
                      Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified allows Server Side...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53241
                      
                      was published
                      Aug 14, 2025 
                    
                  
                    
                      Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward allows Server Side...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-28987
                      
                      was published
                      Aug 14, 2025 
                    
                  
                    
                      During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-7622
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-4655
                      
                      was published
                        for
                        
                          com.liferay.portal:release.dxp.bom
                        
                        (Maven)
                      Aug 9, 2025 
                    
                  
                    
                      Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-25229
                      
                      was published
                      Aug 11, 2025 
                    
                  
                    
                      Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-4581
                      
                      was published
                        for
                        
                          com.liferay.portal:release.dxp.bom
                        
                        (Maven)
                      Aug 9, 2025 
                    
                  
                    
                      A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8772
                      
                      was published
                      Aug 9, 2025 
                    
                  
                    
                      Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-51058
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50234
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      An external service interaction vulnerability in GitLab EE affecting all versions from 15.11...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-9870
                      
                      was published
                      Feb 12, 2025 
                    
                  
                    
                      4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-55399
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8529
                      
                      was published
                      Aug 5, 2025 
                    
                  
                    
                      A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8527
                      
                      was published
                      Aug 5, 2025 
                    
                  
                    
                      Grafana Infinity Datasource Plugin SSRF Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8341
                      
                      was published
                        for
                        
                          github.com/grafana/grafana-infinity-datasource
                        
                        (Go)
                      Aug 4, 2025 
                    
                  
                    
                      A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8520
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      webfinger.js Blind SSRF Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54590
                      
                      was published
                        for
                        
                          webfinger.js
                        
                        (npm)
                      Jul 28, 2025 
                    
                  
                    
                      A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2243
                      
                      was published
                      Apr 4, 2025 
                    
                  
                    
                      A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8228
                      
                      was published
                      Jul 27, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API