GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,681 advisories
Filter by severity
If kdcproxy receives a request for a realm which does not have server addresses defined in its...
High
Unreviewed
CVE-2025-59088
was published
Nov 12, 2025
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass...
Moderate
Unreviewed
CVE-2021-47703
was published
Dec 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core...
Unknown
Unreviewed
CVE-2025-63010
was published
Dec 9, 2025
JDA (Java Discord API) downloads external URLs when updating message components
Moderate
GHSA-93fv-4pm9-xp28
was published
for
net.dv8tion:JDA
(Maven)
Dec 9, 2025
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2025-12832
was published
Dec 9, 2025
ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
Critical
CVE-2025-67494
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat...
Moderate
Unreviewed
CVE-2025-62763
was published
Oct 21, 2025
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows Server Side...
High
Unreviewed
CVE-2025-26487
was published
Dec 8, 2025
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If...
Moderate
Unreviewed
CVE-2024-53696
was published
Mar 7, 2025
A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-14116
was published
Dec 6, 2025
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with...
High
Unreviewed
CVE-2025-59775
was published
Dec 5, 2025
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
High
CVE-2025-65958
was published
for
open-webui
(pip)
Dec 4, 2025
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7...
Low
Unreviewed
CVE-2025-13872
was published
Dec 2, 2025
A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-14008
was published
Dec 4, 2025
A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-14004
was published
Dec 4, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20388
was published
Dec 3, 2025
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
Critical
Unreviewed
CVE-2025-65836
was published
Dec 1, 2025
A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is...
Low
Unreviewed
CVE-2025-9799
was published
Dec 2, 2025
Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host
Moderate
CVE-2025-66405
was published
for
@portkey-ai/gateway
(npm)
Dec 2, 2025
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary...
Moderate
Unreviewed
CVE-2025-27232
was published
Dec 1, 2025
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the...
Moderate
Unreviewed
CVE-2025-13814
was published
Dec 1, 2025
A vulnerability has been found in orionsec orion-ops up to...
Moderate
Unreviewed
CVE-2025-13809
was published
Dec 1, 2025
A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this...
Moderate
Unreviewed
CVE-2025-13796
was published
Dec 1, 2025
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of...
Moderate
Unreviewed
CVE-2025-13789
was published
Nov 30, 2025
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-13378
was published
Nov 27, 2025
ProTip!
Advisories are also available from the
GraphQL API