GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,137 advisories
Filter by severity
czim/file-handling vulnerable to SSRF and directory traversal
Moderate
CVE-2024-47049
was published
for
czim/file-handling
(Composer)
Sep 17, 2024
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-6587
was published
for
litellm
(pip)
Sep 13, 2024
A server-side request forgery issue has been discovered in GitLab EE affecting all versions...
High
Unreviewed
CVE-2024-8635
was published
Sep 12, 2024
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™...
Moderate
Unreviewed
CVE-2021-38132
was published
Sep 12, 2024
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an...
Critical
Unreviewed
CVE-2024-44677
was published
Sep 10, 2024
Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
High
Unreviewed
CVE-2023-37230
was published
Sep 10, 2024
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at ...
Critical
Unreviewed
CVE-2024-44721
was published
Sep 9, 2024
A server side request forgery vulnerability allows a low-privileged user to perform local...
High
Unreviewed
CVE-2024-40718
was published
Sep 7, 2024
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
High
CVE-2024-24759
was published
for
mindsdb
(pip)
Sep 5, 2024
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection')...
High
Unreviewed
CVE-2024-45507
was published
Sep 4, 2024
req may send an unintended request when a malformed URL is provided
Moderate
CVE-2024-45258
was published
for
github.com/imroc/req
(Go)
Aug 26, 2024
Potential access to sensitive URLs via CKAN extensions (SSRF)
Moderate
CVE-2024-43371
was published
for
ckan
(pip)
Aug 21, 2024
Trufflehog vulnerable to Blind SSRF in some Detectors
Low
CVE-2024-43379
was published
for
github.com/trufflesecurity/trufflehog/v3
(Go)
Aug 19, 2024
The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2022-1751
was published
Aug 17, 2024
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows...
Moderate
Unreviewed
CVE-2024-22217
was published
Aug 15, 2024
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC...
Moderate
Unreviewed
CVE-2024-22219
was published
Aug 15, 2024
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected...
Moderate
Unreviewed
CVE-2024-7743
was published
Aug 13, 2024
A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-7740
was published
Aug 13, 2024
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical....
Moderate
Unreviewed
CVE-2024-7742
was published
Aug 13, 2024
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in...
Critical
Unreviewed
CVE-2024-38109
was published
Aug 13, 2024
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints...
Moderate
Unreviewed
CVE-2024-41737
was published
Aug 13, 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-41651
was published
Aug 12, 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7...
Critical
Unreviewed
CVE-2024-41570
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API