GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000
Composer
3,992
Erlang
29
GitHub Actions
16
Go
1,782
Maven
5,000
npm
3,544
NuGet
619
pip
3,134
Pub
10
RubyGems
838
Rust
795
Swift
34
Unreviewed advisories
All unreviewed
5,000
1,024 advisories
Filter by severity
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web...
Moderate
Unreviewed
CVE-2024-6922
was published
Jul 26, 2024
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This...
Moderate
Unreviewed
CVE-2024-38730
was published
Jul 22, 2024
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue...
Moderate
Unreviewed
CVE-2024-38723
was published
Jul 22, 2024
Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP:...
High
Unreviewed
CVE-2024-37942
was published
Jul 22, 2024
Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX...
High
Unreviewed
CVE-2024-38728
was published
Jul 22, 2024
Server-Side Request Forgery (SSRF) vulnerability in WappPress Team WappPress.This issue affects...
Moderate
Unreviewed
CVE-2024-38758
was published
Jul 20, 2024
Apache CXF: SSRF vulnerability via WADL stylesheet parameter
High
CVE-2024-29736
was published
for
org.apache.cxf:cxf-rt-rs-service-description
(Maven)
Jul 19, 2024
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to...
Unknown
Unreviewed
CVE-2024-40898
was published
Jul 18, 2024
Apache StreamPipes has possibility of SSRF in pipeline element installation process
Moderate
CVE-2024-31979
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2024-39739
was published
Jul 15, 2024
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the...
High
Unreviewed
CVE-2024-40544
was published
Jul 12, 2024
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the...
High
Unreviewed
CVE-2024-40543
was published
Jul 12, 2024
Microsoft SharePoint Server Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-32987
was published
Jul 9, 2024
WebFlow Services of SAP Business Workflow allows
an authenticated attacker to enumerate...
Moderate
Unreviewed
CVE-2024-34689
was published
Jul 9, 2024
SAP Transportation Management (Collaboration
Portal) allows an attacker with non-administrative...
Moderate
Unreviewed
CVE-2024-37171
was published
Jul 9, 2024
SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP...
Moderate
Unreviewed
CVE-2024-39598
was published
Jul 9, 2024
Directus Blind SSRF On File Import
Moderate
CVE-2024-39699
was published
for
@directus/api
(npm)
Jul 8, 2024
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20...
Moderate
Unreviewed
CVE-2024-31897
was published
Jul 8, 2024
A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server...
Moderate
Unreviewed
CVE-2024-6095
was published
Jul 6, 2024
Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz:...
High
Unreviewed
CVE-2024-37260
was published
Jul 6, 2024
Server-Side Request Forgery (SSRF) vulnerability in Robert Macchi WP Scraper.This issue affects...
Moderate
Unreviewed
CVE-2024-37208
was published
Jul 6, 2024
Server Side Request Forgery (SSRF) attack in Fedify
High
CVE-2024-39687
was published
for
@fedify/fedify
(npm)
Jul 5, 2024
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via...
Critical
Unreviewed
CVE-2024-29319
was published
Jul 5, 2024
ShopXO Server-Side Request Forgery Vulnerability
Moderate
CVE-2024-6524
was published
for
shopxo/shopxo
(Composer)
Jul 5, 2024
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream...
High
Unreviewed
CVE-2024-5736
was published
Jul 3, 2024
ProTip!
Advisories are also available from the
GraphQL API