GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
300 advisories
Filter by severity
Apache Batik information disclosure vulnerability
Moderate
CVE-2022-44730
was published
for
org.apache.xmlgraphics:batik-script
(Maven)
Aug 22, 2023
Apache XML Graphics Batik Server-Side Request Forgery vulnerability
High
CVE-2022-44729
was published
for
org.apache.xmlgraphics:batik-bridge
(Maven)
Aug 22, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
High
CVE-2023-40033
was published
for
flarum/core
(Composer)
Aug 16, 2023
OpenRefine Server-Side Request Forgery vulnerability
Moderate
CVE-2022-41401
was published
for
org.openrefine:main
(Maven)
Aug 4, 2023
Apache Superset Server-Side Request Forgery vulnerability
Moderate
CVE-2023-25504
was published
for
apache-superset
(pip)
Jul 6, 2023
WPGraphQL Plugin vulnerable to Server Side Request Forgery (SSRF)
Moderate
CVE-2023-23684
was published
for
wp-graphql/wp-graphql
(Composer)
Jun 30, 2023
PlantUML Server-Side Request Forgery vulnerability
High
CVE-2023-3432
was published
for
net.sourceforge.plantuml:plantuml
(Maven)
Jun 27, 2023
Moodle vulnerable to Server Side Request Forgery
High
CVE-2023-35133
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
Moderate
CVE-2023-32683
was published
for
matrix-synapse
(pip)
Jun 6, 2023
imgproxy is vulnerable to Server-Side Request Forgery
Moderate
CVE-2023-30019
was published
for
github.com/imgproxy/imgproxy/v3
(Go)
May 8, 2023
Access control issues in blackbox_exporter
High
CVE-2023-26735
was published
for
github.com/prometheus/blackbox_exporter
(Go)
Apr 26, 2023
yuan1994 tpAdmin vulnerable to Server-Side Request Forgery
Moderate
CVE-2023-1971
was published
for
yuan1994/tpadmin
(Composer)
Apr 10, 2023
SvelteKit framework has Insufficient CSRF protection for CORS requests
High
CVE-2023-29008
was published
for
@sveltejs/kit
(npm)
Apr 7, 2023
Appwrite Server-Side Request Forgery vulnerability
High
CVE-2023-27159
was published
for
appwrite/server-ce
(Composer)
Mar 31, 2023
request-baskets vulnerable to Server-Side Request Forgery
Moderate
CVE-2023-27163
was published
for
github.com/darklynx/request-baskets
(Go)
Mar 31, 2023
OpenAPI Generator vulnerable to Server-Side Request Forgery
Critical
CVE-2023-27162
was published
for
org.openapitools:openapi-generator-project
(Maven)
Mar 31, 2023
CairoSVG improperly processes SVG files loaded from external resources
High
CVE-2023-27586
was published
for
CairoSVG
(pip)
Mar 20, 2023
Server-Side Request Forgery in Request
Moderate
CVE-2023-28155
was published
for
@cypress/request
(npm)
Mar 16, 2023
Moodle vulnerable to Server-Side Request Forgery
High
CVE-2021-36396
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Directus vulnerable to Server-Side Request Forgery On File Import
Moderate
CVE-2023-26492
was published
for
directus
(npm)
Mar 3, 2023
Server-Side Request Forgery in Plone CMS
High
CVE-2021-33926
was published
for
Plone
(pip)
Feb 17, 2023
Paranoidhttp Server-Side Request Forgery vulnerability
High
CVE-2023-24623
was published
for
github.com/hakobe/paranoidhttp
(Go)
Jan 30, 2023
Withdrawn: safeurl-python contains Server-Side Request Forgery
Moderate
GHSA-rw83-v3pw-m362
was published
for
safeurl-python
(pip)
Jan 30, 2023
•
withdrawn
safeurl-python contains Server-Side Request Forgery
Moderate
CVE-2023-24622
was published
for
safeurl-python
(pip)
Jan 27, 2023
ProTip!
Advisories are also available from the
GraphQL API