GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,297
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
920
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
134 advisories
Filter by severity
OpenShift Console Server Side Request Forgery vulnerability
Moderate
CVE-2024-6538
was published
for
github.com/openshift/console
(Go)
Nov 25, 2024
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
Moderate
GHSA-5q9x-554g-9jgg
was published
for
surrealdb
(Rust)
Apr 11, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-32372
was published
for
DotNetNuke.Core
(NuGet)
Apr 9, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-28094
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Email Settings
Moderate
CVE-2025-28093
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Image Upload
Moderate
CVE-2025-28092
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
Moderate
CVE-2025-31116
was published
for
mobsf
(pip)
Mar 31, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
composio Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-8952
was published
for
composio-core
(pip)
Mar 20, 2025
Rembg allows SSRF via /api/remove
Moderate
CVE-2025-25301
was published
for
rembg
(pip)
Mar 11, 2025
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
Moderate
CVE-2024-45291
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-26366
was published
for
magento/community-edition
(Composer)
Oct 13, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29292
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29291
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Memos Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-22952
was published
for
github.com/usememos/memos
(Go)
Feb 27, 2025
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull
Moderate
CVE-2024-34068
was published
for
github.com/pterodactyl/wings
(Go)
May 3, 2024
SSRF in sliver teamserver
Moderate
CVE-2025-27090
was published
for
github.com/bishopfox/sliver
(Go)
Feb 19, 2025
Apache Batik information disclosure vulnerability
Moderate
CVE-2022-44730
was published
for
org.apache.xmlgraphics:batik-script
(Maven)
Aug 22, 2023
Apache HugeGraph-Hubble: SSRF in Hubble connection page
Moderate
CVE-2024-27347
was published
for
org.apache.hugegraph:hugegraph-hubble
(Maven)
Apr 22, 2024
Apache Superset Server-Side Request Forgery vulnerability
Moderate
CVE-2023-25504
was published
for
apache-superset
(pip)
Jul 6, 2023
Blind SSRF Leads to Port Scan by using Webhooks
Moderate
CVE-2024-29035
was published
for
Umbraco.Cms.Core
(NuGet)
Apr 17, 2024
Server-Side Request Forgery (SSRF) in activitypub_federation
Moderate
CVE-2025-25194
was published
for
activitypub_federation
(Rust)
Feb 10, 2025
imgproxy is vulnerable to SSRF against 0.0.0.0
Moderate
CVE-2025-24354
was published
for
github.com/imgproxy/imgproxy
(Go)
Jan 27, 2025
Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify
Moderate
CVE-2025-23221
was published
for
@fedify/fedify
(npm)
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API