GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
47 advisories
Filter by severity
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Low
CVE-2025-62505
was published
for
@lobehub/chat
(npm)
Oct 17, 2025
HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery ...
Low
Unreviewed
CVE-2025-31993
was published
Oct 12, 2025
CVE-2025-54087 is a server-side request forgery
vulnerability in Secure Access prior to version...
Low
Unreviewed
CVE-2025-54087
was published
Oct 2, 2025
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value...
Low
Unreviewed
CVE-2025-59436
was published
Sep 16, 2025
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value...
Low
Unreviewed
CVE-2025-59437
was published
Sep 16, 2025
Mautic vulnerable to SSRF via webhook function
Low
CVE-2025-9821
was published
for
mautic/core
(Composer)
Sep 3, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request...
Low
Unreviewed
CVE-2025-54234
was published
Aug 18, 2025
The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery...
Low
Unreviewed
CVE-2025-8013
was published
Aug 15, 2025
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an...
Low
Unreviewed
CVE-2025-42988
was published
Jun 10, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may...
Low
Unreviewed
CVE-2025-2987
was published
Apr 22, 2025
open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.
Low
Unreviewed
CVE-2025-29446
was published
Apr 21, 2025
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center)...
Low
Unreviewed
CVE-2025-27430
was published
Mar 11, 2025
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input...
Low
Unreviewed
CVE-2024-52606
was published
Feb 11, 2025
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to...
Low
Unreviewed
CVE-2023-6195
was published
Jan 31, 2025
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form &...
Low
Unreviewed
CVE-2024-13450
was published
Jan 25, 2025
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. ...
Low
Unreviewed
CVE-2024-42182
was published
Jan 23, 2025
QOS.CH logback-core Server-Side Request Forgery vulnerability
Low
CVE-2024-12801
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 19, 2024
Northern.tech Hosted Mender before 2024.07.11 allows SSRF.
Low
Unreviewed
CVE-2024-47190
was published
Nov 8, 2024
ProTip!
Advisories are also available from the
GraphQL API