GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,957
Maven
5,000+
npm
4,607
NuGet
787
pip
4,306
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
894 advisories
Filter by severity
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-20958
was published
Jan 13, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Moderate
CVE-2026-22772
was published
for
github.com/sigstore/fulcio
(Go)
Jan 13, 2026
During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that...
Moderate
Unreviewed
CVE-2025-7622
was published
Aug 12, 2025
Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification
Moderate
CVE-2025-34469
was published
for
cowrie
(pip)
Dec 20, 2025
Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated...
Moderate
Unreviewed
CVE-2025-65784
was published
Jan 13, 2026
Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0...
Moderate
Unreviewed
CVE-2026-0600
was published
Jan 15, 2026
Umbraco CMS contains a server-side request forgery vulnerability
Moderate
CVE-2021-47776
was published
for
UmbracoCms
(NuGet)
Jan 15, 2026
The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request...
Moderate
Unreviewed
CVE-2025-14793
was published
Jan 16, 2026
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to...
Moderate
Unreviewed
CVE-2026-23768
was published
Jan 16, 2026
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the...
Moderate
Unreviewed
CVE-2026-1062
was published
Jan 17, 2026
Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows...
Moderate
Unreviewed
CVE-2025-49374
was published
Oct 22, 2025
Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates...
Moderate
Unreviewed
CVE-2025-62988
was published
Oct 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side...
Moderate
Unreviewed
CVE-2025-67989
was published
Dec 16, 2025
Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers...
Moderate
Unreviewed
CVE-2025-49917
was published
Oct 22, 2025
Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side...
Moderate
Unreviewed
CVE-2025-69014
was published
Dec 30, 2025
Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core...
Moderate
Unreviewed
CVE-2025-63010
was published
Dec 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker allows...
Moderate
Unreviewed
CVE-2025-68893
was published
Dec 29, 2025
Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy allows Server Side Request...
Moderate
Unreviewed
CVE-2025-59138
was published
Dec 31, 2025
Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper...
Moderate
Unreviewed
CVE-2025-62088
was published
Dec 31, 2025
Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2026-21859
was published
for
github.com/axllent/mailpit
(Go)
Jan 6, 2026
Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check API
Moderate
CVE-2026-23845
was published
for
github.com/axllent/mailpit
(Go)
Jan 21, 2026
Keycloak’s OpenID Connect Dynamic Client Registration feature affected by Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-1180
was published
for
org.keycloak:keycloak-adapter-core
(Maven)
Jan 20, 2026
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods PhotoMe photome allows Server Side...
Moderate
Unreviewed
CVE-2026-24381
was published
Jan 22, 2026
Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting...
Moderate
Unreviewed
CVE-2026-24360
was published
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API