GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,109
Maven
5,000+
npm
3,765
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
887
Swift
37
Unreviewed advisories
All unreviewed
5,000+
425 advisories
Filter by severity
A vulnerability classified as critical has been found in 60IndexPage up to 1.8.5. This affects an...
High
Unreviewed
CVE-2024-0945
was published
Jan 26, 2024
A vulnerability classified as critical was found in 60IndexPage up to 1.8.5. This vulnerability...
High
Unreviewed
CVE-2024-0946
was published
Jan 26, 2024
TrueLayer.Client SSRF when fetching payment or payment provider
High
CVE-2024-23838
was published
for
TrueLayer.Client
(NuGet)
Jan 30, 2024
Apache ServiceComb Service-Center Server-Side Request Forgery vulnerability
High
CVE-2023-44313
was published
for
github.com/apache/servicecomb-service-center
(Go)
Jan 31, 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x,...
High
Unreviewed
CVE-2024-21893
was published
Jan 31, 2024
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could...
High
Unreviewed
CVE-2023-50165
was published
Jan 31, 2024
XXL-JOB vulnerable to Server-Side Request Forgery
High
CVE-2024-24113
was published
for
com.xuxueli:xxl-job
(Maven)
Feb 8, 2024
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery ...
High
Unreviewed
CVE-2024-22873
was published
Feb 26, 2024
An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can...
High
Unreviewed
CVE-2022-34269
was published
Feb 29, 2024
SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
High
CVE-2024-29190
was published
for
mobsfscan
(pip)
Mar 22, 2024
gradio Server-Side Request Forgery vulnerability
High
CVE-2024-2206
was published
for
gradio
(pip)
Mar 27, 2024
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates —...
High
Unreviewed
CVE-2023-34370
was published
Mar 28, 2024
Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada:...
High
Unreviewed
CVE-2023-39313
was published
Mar 28, 2024
Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks...
High
Unreviewed
CVE-2024-23500
was published
Mar 28, 2024
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects...
High
Unreviewed
CVE-2023-36679
was published
Mar 28, 2024
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow...
High
Unreviewed
CVE-2024-27775
was published
Mar 28, 2024
Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated...
High
Unreviewed
CVE-2024-25187
was published
Apr 2, 2024
The CloudStack management server and secondary storage VM could be tricked into making requests...
High
Unreviewed
CVE-2024-29007
was published
Apr 4, 2024
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information...
High
Unreviewed
CVE-2024-27620
was published
Apr 6, 2024
Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize...
High
Unreviewed
CVE-2024-31288
was published
Apr 7, 2024
WildFly Elytron: SSRF security issue
High
CVE-2024-1233
was published
for
org.wildfly.security:wildfly-elytron-realm-token
(Maven)
Apr 9, 2024
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via...
High
Unreviewed
CVE-2024-32407
was published
Apr 22, 2024
Next.js Server-Side Request Forgery in Server Actions
High
CVE-2024-34351
was published
for
next
(npm)
May 9, 2024
An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4...
High
Unreviewed
CVE-2024-33250
was published
May 14, 2024
Withdrawn Advisory: Weights and Biases (wandb) has a Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-4642
was published
for
wandb
(pip)
May 16, 2024
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API