GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,161 advisories
Filter by severity
Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
High
Unreviewed
CVE-2023-37230
was published
Sep 10, 2024
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at ...
Critical
Unreviewed
CVE-2024-44721
was published
Sep 9, 2024
A server side request forgery vulnerability allows a low-privileged user to perform local...
High
Unreviewed
CVE-2024-40718
was published
Sep 7, 2024
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
High
CVE-2024-24759
was published
for
mindsdb
(pip)
Sep 5, 2024
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection')...
High
Unreviewed
CVE-2024-45507
was published
Sep 4, 2024
req may send an unintended request when a malformed URL is provided
Moderate
CVE-2024-45258
was published
for
github.com/imroc/req
(Go)
Aug 26, 2024
Potential access to sensitive URLs via CKAN extensions (SSRF)
Moderate
CVE-2024-43371
was published
for
ckan
(pip)
Aug 21, 2024
Trufflehog vulnerable to Blind SSRF in some Detectors
Low
CVE-2024-43379
was published
for
github.com/trufflesecurity/trufflehog/v3
(Go)
Aug 19, 2024
The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2022-1751
was published
Aug 17, 2024
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC...
Moderate
Unreviewed
CVE-2024-22219
was published
Aug 15, 2024
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows...
Moderate
Unreviewed
CVE-2024-22217
was published
Aug 15, 2024
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical....
Moderate
Unreviewed
CVE-2024-7742
was published
Aug 13, 2024
A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-7740
was published
Aug 13, 2024
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected...
Moderate
Unreviewed
CVE-2024-7743
was published
Aug 13, 2024
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in...
Critical
Unreviewed
CVE-2024-38109
was published
Aug 13, 2024
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints...
Moderate
Unreviewed
CVE-2024-41737
was published
Aug 13, 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-41651
was published
Aug 12, 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7...
Critical
Unreviewed
CVE-2024-41570
was published
Aug 12, 2024
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH...
Critical
Unreviewed
CVE-2024-23788
was published
Aug 9, 2024
CometVisu Backend for openHAB affected by SSRF/XSS
High
CVE-2024-42467
was published
for
org.openhab.ui.bundles:org.openhab.ui.cometvisu
(Maven)
Aug 9, 2024
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in...
High
Unreviewed
CVE-2024-6522
was published
Aug 7, 2024
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft...
High
Unreviewed
CVE-2024-38206
was published
Aug 7, 2024
memos vulnerable to Server-Side Request Forgery in /o/get/httpmeta
Moderate
CVE-2024-29028
was published
for
github.com/usememos/memos
(Go)
Aug 5, 2024
ProTip!
Advisories are also available from the
GraphQL API