GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
531 advisories
Filter by severity
If kdcproxy receives a request for a realm which does not have server addresses defined in its...
High
Unreviewed
CVE-2025-59088
was published
Nov 12, 2025
A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer...
High
Unreviewed
CVE-2025-60541
was published
Nov 6, 2025
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
Jellysweep uses uncontrolled data in image cache API endpoint
High
CVE-2025-64178
was published
for
github.com/jon4hz/jellysweep
(Go)
Nov 4, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-10145
was published
Oct 28, 2025
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce...
High
Unreviewed
CVE-2025-10861
was published
Oct 24, 2025
Angular SSR has a Server-Side Request Forgery (SSRF) flaw
High
CVE-2025-62427
was published
for
@angular/ssr
(npm)
Oct 16, 2025
Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x...
High
Unreviewed
CVE-2025-9868
was published
Oct 8, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High
CVE-2025-61735
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform...
High
Unreviewed
CVE-2025-20371
was published
Oct 1, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34225
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34228
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34233
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34231
was published
Sep 29, 2025
StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without ...
High
Unreviewed
CVE-2025-26515
was published
Sep 19, 2025
Dragonfly vulnerable to server-side request forgery
High
CVE-2025-59346
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2025-59527
was published
for
flowise
(npm)
Sep 15, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18...
High
Unreviewed
CVE-2025-6454
was published
Sep 12, 2025
Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server...
High
Unreviewed
CVE-2025-49430
was published
Sep 9, 2025
A server-side request forgery security issue exists within Rockwell Automation ThinManager®...
High
Unreviewed
CVE-2025-9065
was published
Sep 9, 2025
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
High
CVE-2025-58179
was published
for
@astrojs/cloudflare
(npm)
Sep 4, 2025
PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
High
CVE-2025-54370
was published
for
phpoffice/phpspreadsheet
(Composer)
Aug 25, 2025
ProTip!
Advisories are also available from the
GraphQL API