GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,097
Erlang
29
GitHub Actions
19
Go
1,925
Maven
5,000+
npm
3,657
NuGet
638
pip
3,264
Pub
10
RubyGems
873
Rust
823
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
170 advisories
Filter by severity
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-41651
was published
Aug 12, 2024
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via...
Critical
Unreviewed
CVE-2024-47222
was published
Sep 23, 2024
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an...
Critical
Unreviewed
CVE-2024-44677
was published
Sep 10, 2024
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at ...
Critical
Unreviewed
CVE-2024-44721
was published
Sep 9, 2024
A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6...
Critical
Unreviewed
CVE-2024-27565
was published
Mar 5, 2024
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS...
Critical
Unreviewed
CVE-2024-27561
was published
Mar 5, 2024
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in...
Critical
Unreviewed
CVE-2024-38109
was published
Aug 13, 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7...
Critical
Unreviewed
CVE-2024-41570
was published
Aug 12, 2024
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and...
Critical
Unreviewed
CVE-2024-25294
was published
Mar 20, 2024
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to...
Critical
Unreviewed
CVE-2024-40898
was published
Jul 18, 2024
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021...
Critical
Unreviewed
CVE-2021-34473
was published
May 24, 2022
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen...
Critical
Unreviewed
CVE-2021-40438
was published
May 24, 2022
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via...
Critical
Unreviewed
CVE-2024-29319
was published
Jul 5, 2024
An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in...
Critical
Unreviewed
CVE-2024-33857
was published
May 7, 2024
An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can...
Critical
Unreviewed
CVE-2023-46295
was published
May 1, 2024
External server-side request vulnerability in MESbook 20221021.03 version, which could allow a...
Critical
Unreviewed
CVE-2024-6424
was published
Jul 1, 2024
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
Critical
Unreviewed
CVE-2024-36675
was published
Jun 5, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex...
Critical
Unreviewed
CVE-2024-3149
was published
Jun 6, 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job...
Critical
Unreviewed
CVE-2023-48022
was published
Nov 28, 2023
A server-side request forgery (SSRF) was discovered in the Akana Community Manager Developer...
Critical
Unreviewed
CVE-2024-2796
was published
Apr 18, 2024
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2023-41449
was published
Sep 28, 2023
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive...
Critical
Unreviewed
CVE-2023-42398
was published
Sep 15, 2023
Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF).
Critical
Unreviewed
CVE-2022-42183
was published
Jul 31, 2023
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery...
Critical
Unreviewed
CVE-2023-1895
was published
Jul 6, 2023
Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code...
Critical
Unreviewed
CVE-2023-35175
was published
Jun 30, 2023
ProTip!
Advisories are also available from the
GraphQL API