GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,479
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,231 advisories
Filter by severity
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote...
Moderate
Unreviewed
CVE-2022-28117
was published
Apr 29, 2022
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF...
Critical
Unreviewed
CVE-2022-29556
was published
Apr 29, 2022
Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).
Critical
Unreviewed
CVE-2022-27469
was published
Apr 27, 2022
Server side request forgery in gibbon
Critical
CVE-2022-27311
was published
for
gibbon
(RubyGems)
Apr 26, 2022
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via ...
Critical
Unreviewed
CVE-2022-27429
was published
Apr 26, 2022
A vulnerability in all versions of SCT/SCT Pro prior to version 14.2.2 allows a remote...
Critical
Unreviewed
CVE-2021-36203
was published
Apr 23, 2022
Server-Side Request Forgery (SSRF) in Shopware
High
CVE-2022-24871
was published
for
shopware/core
(Composer)
Apr 22, 2022
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
Moderate
Unreviewed
CVE-2007-6758
was published
Apr 21, 2022
Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector
High
CVE-2022-29153
was published
for
github.com/hashicorp/consul
(Go)
Apr 20, 2022
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external...
High
Unreviewed
CVE-2022-1037
was published
Apr 19, 2022
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to...
Critical
Unreviewed
CVE-2022-26499
was published
Apr 16, 2022
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the...
High
Unreviewed
CVE-2022-27426
was published
Apr 16, 2022
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an...
High
Unreviewed
CVE-2022-22339
was published
Apr 9, 2022
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting...
Moderate
Unreviewed
CVE-2020-27375
was published
Apr 8, 2022
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an...
High
Unreviewed
CVE-2021-36202
was published
Apr 8, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
Server side request forgery in LiveHelperChat
High
CVE-2022-1213
was published
for
remdex/livehelperchat
(Composer)
Apr 6, 2022
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Critical
Unreviewed
CVE-2022-0939
was published
Apr 5, 2022
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Critical
Unreviewed
CVE-2022-0990
was published
Apr 5, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14...
Moderate
Unreviewed
CVE-2022-1188
was published
Apr 5, 2022
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE...
High
Unreviewed
CVE-2022-0425
was published
Apr 3, 2022
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact...
High
Unreviewed
CVE-2021-33581
was published
Apr 1, 2022
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to...
High
Unreviewed
CVE-2022-1191
was published
Apr 1, 2022
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
Moderate
Unreviewed
CVE-2022-27907
was published
Mar 31, 2022
Server side request forgery in C1 CMS
High
CVE-2022-24789
was published
for
C1CMS.Assemblies
(NuGet)
Mar 30, 2022
ProTip!
Advisories are also available from the
GraphQL API