GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
423 advisories
Filter by severity
Server-Side Request Forgery in UReport
High
CVE-2020-21122
was published
for
com.bstek.ureport:ureport2-console
(Maven)
Sep 20, 2021
Server-Side Request Forgery vulnerability in concrete5
High
CVE-2021-22958
was published
for
concrete5/concrete5
(Composer)
Oct 12, 2021
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of...
High
Unreviewed
CVE-2021-3552
was published
Nov 25, 2021
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
High
Unreviewed
CVE-2021-43296
was published
Dec 1, 2021
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted...
High
Unreviewed
CVE-2021-40809
was published
Dec 2, 2021
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery ...
High
Unreviewed
CVE-2021-39057
was published
Dec 14, 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14...
High
Unreviewed
CVE-2021-39935
was published
Dec 14, 2021
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0...
High
Unreviewed
CVE-2021-22054
was published
Dec 18, 2021
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of...
High
Unreviewed
CVE-2021-3959
was published
Dec 17, 2021
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3...
High
Unreviewed
CVE-2021-22056
was published
Dec 21, 2021
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint...
High
Unreviewed
CVE-2017-17697
was published
May 13, 2022
A server-side request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250...
High
Unreviewed
CVE-2018-7516
was published
May 13, 2022
Server-Side Request Forgery in gogs webhook
High
CVE-2022-1285
was published
for
gogs.io/gogs
(Go)
Jun 3, 2022
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is...
High
Unreviewed
CVE-2020-35558
was published
May 24, 2022
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal...
High
Unreviewed
CVE-2022-38212
was published
Dec 29, 2022
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal...
High
Unreviewed
CVE-2022-38211
was published
Dec 29, 2022
Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal...
High
Unreviewed
CVE-2022-38203
was published
Dec 29, 2022
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and...
High
Unreviewed
CVE-2020-22983
was published
May 14, 2022
** DISPUTED ** The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the...
High
Unreviewed
CVE-2017-16870
was published
May 14, 2022
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading...
High
Unreviewed
CVE-2017-9066
was published
May 14, 2022
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to...
High
Unreviewed
CVE-2018-15517
was published
May 14, 2022
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api...
High
Unreviewed
CVE-2018-15657
was published
May 14, 2022
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main...
High
Unreviewed
CVE-2019-5725
was published
May 14, 2022
The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack,...
High
Unreviewed
CVE-2018-18569
was published
May 14, 2022
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before...
High
Unreviewed
CVE-2018-18646
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API