GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,697 advisories
Filter by severity
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
High
CVE-2025-68150
was published
for
parse-server
(npm)
Dec 16, 2025
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows...
Low
Unreviewed
CVE-2023-53899
was published
Dec 16, 2025
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network...
High
Unreviewed
CVE-2025-14443
was published
Dec 16, 2025
Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side...
Unknown
Unreviewed
CVE-2025-67989
was published
Dec 16, 2025
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in...
Moderate
Unreviewed
CVE-2023-53893
was published
Dec 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions...
Moderate
Unreviewed
CVE-2025-66436
was published
Dec 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method...
Moderate
Unreviewed
CVE-2025-66435
was published
Dec 15, 2025
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig...
Critical
Unreviewed
CVE-2025-66844
was published
Dec 15, 2025
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass
Moderate
CVE-2025-13281
was published
for
k8s.io/kubernetes
(Go)
Dec 15, 2025
The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized...
Moderate
Unreviewed
CVE-2025-11970
was published
Dec 13, 2025
PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
Moderate
CVE-2025-14518
was published
for
tech.powerjob:powerjob-common
(Maven)
Dec 11, 2025
A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-14516
was published
Dec 11, 2025
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator...
Moderate
Unreviewed
CVE-2025-11467
was published
Dec 11, 2025
BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated...
Moderate
Unreviewed
CVE-2020-36884
was published
Dec 10, 2025
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown...
High
Unreviewed
CVE-2025-65512
was published
Dec 10, 2025
Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-65513
was published
for
mcp-fetch-server
(npm)
Dec 10, 2025
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass...
Moderate
Unreviewed
CVE-2021-47703
was published
Dec 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core...
Moderate
Unreviewed
CVE-2025-63010
was published
Dec 9, 2025
JDA (Java Discord API) downloads external URLs when updating message components
Moderate
GHSA-93fv-4pm9-xp28
was published
for
net.dv8tion:JDA
(Maven)
Dec 9, 2025
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2025-12832
was published
Dec 9, 2025
ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
Critical
CVE-2025-67494
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows Server Side...
High
Unreviewed
CVE-2025-26487
was published
Dec 8, 2025
A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-14116
was published
Dec 6, 2025
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with...
High
Unreviewed
CVE-2025-59775
was published
Dec 5, 2025
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
High
CVE-2025-65958
was published
for
open-webui
(pip)
Dec 4, 2025
ProTip!
Advisories are also available from the
GraphQL API