GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
377 advisories
Filter by severity
NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an...
High
Unreviewed
CVE-2025-33203
was published
Nov 25, 2025
Azure Monitor Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-62207
was published
Nov 21, 2025
If kdcproxy receives a request for a realm which does not have server addresses defined in its...
High
Unreviewed
CVE-2025-59088
was published
Nov 12, 2025
A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer...
High
Unreviewed
CVE-2025-60541
was published
Nov 6, 2025
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy...
High
Unreviewed
CVE-2024-43204
was published
Jul 10, 2025
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak...
High
Unreviewed
CVE-2024-43394
was published
Jul 10, 2025
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by...
High
Unreviewed
CVE-2023-46303
was published
Oct 22, 2023
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side...
High
Unreviewed
CVE-2025-10145
was published
Oct 28, 2025
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce...
High
Unreviewed
CVE-2025-10861
was published
Oct 24, 2025
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x,...
High
Unreviewed
CVE-2024-21893
was published
Jan 31, 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability.
High
Unreviewed
CVE-2022-41040
was published
Oct 4, 2022
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may...
High
Unreviewed
CVE-2021-21975
was published
May 24, 2022
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8...
High
Unreviewed
CVE-2019-9621
was published
May 24, 2022
A server-side request forgery security issue exists within Rockwell Automation ThinManager®...
High
Unreviewed
CVE-2025-9065
was published
Sep 9, 2025
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input...
High
Unreviewed
CVE-2024-3152
was published
Jun 6, 2024
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34228
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34225
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34231
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
High
Unreviewed
CVE-2025-34233
was published
Sep 29, 2025
Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x...
High
Unreviewed
CVE-2025-9868
was published
Oct 8, 2025
Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system...
High
Unreviewed
CVE-2024-11836
was published
Dec 13, 2024
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform...
High
Unreviewed
CVE-2025-20371
was published
Oct 1, 2025
StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without ...
High
Unreviewed
CVE-2025-26515
was published
Sep 19, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18...
High
Unreviewed
CVE-2025-6454
was published
Sep 12, 2025
Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server...
High
Unreviewed
CVE-2025-49430
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API