GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
534 advisories
Filter by severity
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
High
CVE-2025-27152
was published
for
axios
(npm)
Mar 7, 2025
new-api is vulnerable to SSRF Bypass
High
CVE-2025-62155
was published
for
github.com/QuantumNous/new-api
(Go)
Nov 24, 2025
NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an...
High
Unreviewed
CVE-2025-33203
was published
Nov 25, 2025
Azure Monitor Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-62207
was published
Nov 21, 2025
If kdcproxy receives a request for a realm which does not have server addresses defined in its...
High
Unreviewed
CVE-2025-59088
was published
Nov 12, 2025
Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension
High
CVE-2021-36043
was published
for
magento/community-edition
(Composer)
May 24, 2022
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer...
High
Unreviewed
CVE-2025-60541
was published
Nov 6, 2025
Jellysweep uses uncontrolled data in image cache API endpoint
High
CVE-2025-64178
was published
for
github.com/jon4hz/jellysweep
(Go)
Nov 4, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High
CVE-2025-61735
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy...
High
Unreviewed
CVE-2024-43204
was published
Jul 10, 2025
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak...
High
Unreviewed
CVE-2024-43394
was published
Jul 10, 2025
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by...
High
Unreviewed
CVE-2023-46303
was published
Oct 22, 2023
Apache Batik vulnerable to Server-Side Request Forgery
High
CVE-2022-40146
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-10145
was published
Oct 28, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce...
High
Unreviewed
CVE-2025-10861
was published
Oct 24, 2025
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x,...
High
Unreviewed
CVE-2024-21893
was published
Jan 31, 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability.
High
Unreviewed
CVE-2022-41040
was published
Oct 4, 2022
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may...
High
Unreviewed
CVE-2021-21975
was published
May 24, 2022
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8...
High
Unreviewed
CVE-2019-9621
was published
May 24, 2022
A server-side request forgery security issue exists within Rockwell Automation ThinManager®...
High
Unreviewed
CVE-2025-9065
was published
Sep 9, 2025
Angular SSR has a Server-Side Request Forgery (SSRF) flaw
High
CVE-2025-62427
was published
for
@angular/ssr
(npm)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API