GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
519 advisories
Filter by severity
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
Moderate
Unreviewed
CVE-2007-6758
was published
Apr 21, 2022
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting...
Moderate
Unreviewed
CVE-2020-27375
was published
Apr 8, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14...
Moderate
Unreviewed
CVE-2022-1188
was published
Apr 5, 2022
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
Moderate
Unreviewed
CVE-2022-27907
was published
Mar 31, 2022
Server-Side Request Forgery in Apache Dubbo
Moderate
CVE-2021-25640
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed...
Moderate
Unreviewed
CVE-2021-43954
was published
Mar 15, 2022
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2021-39051
was published
Mar 15, 2022
SSRF in repository migration
Moderate
GHSA-q347-cg56-pcq4
was published
for
gogs.io/gogs
(Go)
Mar 14, 2022
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
swagger-ui
(npm)
Mar 12, 2022
SSRF in repository migration
Moderate
CVE-2022-0870
was published
for
gogs.io/gogs
(Go)
Mar 12, 2022
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
Moderate
Unreviewed
CVE-2022-24333
was published
Feb 26, 2022
Server Side Request Forgery in Grafana
Moderate
CVE-2020-13379
was published
for
github.com/grafana/grafana
(Go)
Feb 15, 2022
Server Side Request Forgery (SSRF) in Kubernetes
Moderate
CVE-2020-8555
was published
for
k8s.io/kubernetes
(Go)
Feb 15, 2022
Server-Side Request Forgery in Karaf
Moderate
CVE-2020-11980
was published
for
org.apache.karaf.management:org.apache.karaf.management.server
(Maven)
Feb 10, 2022
Server-Side Request Forgery in @peertube/embed-api
Moderate
CVE-2022-0508
was published
for
@peertube/embed-api
(npm)
Feb 9, 2022
Gitea displaying raw OpenID error in UI
Moderate
CVE-2021-45325
was published
for
github.com/go-gitea/gitea
(Go)
Feb 9, 2022
Server-Side Request Forgery in calibreweb
Moderate
CVE-2022-0339
was published
for
calibreweb
(pip)
Feb 1, 2022
SSRF vulnerability in jupyter-server-proxy
Moderate
CVE-2022-21697
was published
for
jupyter-server-proxy
(pip)
Jan 27, 2022
Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery...
Moderate
Unreviewed
CVE-2021-36349
was published
Jan 25, 2022
Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.x, between...
Moderate
Unreviewed
CVE-2021-39927
was published
Jan 19, 2022
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview...
Moderate
Unreviewed
CVE-2021-41809
was published
Jan 19, 2022
PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when...
Moderate
Unreviewed
CVE-2022-22702
was published
Jan 11, 2022
Server-Side Request Forgery in Apache Kylin
Moderate
CVE-2021-27738
was published
for
org.apache.kylin:kylin
(Maven)
Jan 8, 2022
The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows)...
Moderate
Unreviewed
CVE-2021-34425
was published
Dec 15, 2021
ProTip!
Advisories are also available from the
GraphQL API