GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
715 advisories
Filter by severity
Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy allows Server Side Request...
Moderate
Unreviewed
CVE-2025-59138
was published
Dec 31, 2025
Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper...
Moderate
Unreviewed
CVE-2025-62088
was published
Dec 31, 2025
A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function...
Moderate
Unreviewed
CVE-2025-15373
was published
Dec 31, 2025
A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the...
Moderate
Unreviewed
CVE-2025-15264
was published
Dec 30, 2025
Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side...
Moderate
Unreviewed
CVE-2025-69014
was published
Dec 30, 2025
Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker allows...
Moderate
Unreviewed
CVE-2025-68893
was published
Dec 29, 2025
A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function...
Moderate
Unreviewed
CVE-2025-15098
was published
Dec 26, 2025
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management...
Moderate
Unreviewed
CVE-2019-25251
was published
Dec 24, 2025
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers...
Moderate
Unreviewed
CVE-2021-47715
was published
Dec 23, 2025
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request...
Moderate
Unreviewed
CVE-2025-14277
was published
Dec 18, 2025
Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side...
Moderate
Unreviewed
CVE-2025-67989
was published
Dec 16, 2025
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in...
Moderate
Unreviewed
CVE-2023-53893
was published
Dec 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method...
Moderate
Unreviewed
CVE-2025-66435
was published
Dec 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions...
Moderate
Unreviewed
CVE-2025-66436
was published
Dec 15, 2025
The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized...
Moderate
Unreviewed
CVE-2025-11970
was published
Dec 13, 2025
A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-14516
was published
Dec 11, 2025
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator...
Moderate
Unreviewed
CVE-2025-11467
was published
Dec 11, 2025
BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated...
Moderate
Unreviewed
CVE-2020-36884
was published
Dec 10, 2025
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass...
Moderate
Unreviewed
CVE-2021-47703
was published
Dec 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core...
Moderate
Unreviewed
CVE-2025-63010
was published
Dec 9, 2025
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2025-12832
was published
Dec 9, 2025
A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-14116
was published
Dec 6, 2025
A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-14008
was published
Dec 4, 2025
A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-14004
was published
Dec 4, 2025
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary...
Moderate
Unreviewed
CVE-2025-27232
was published
Dec 1, 2025
ProTip!
Advisories are also available from the
GraphQL API