GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,168
Erlang
30
GitHub Actions
19
Go
1,978
Maven
5,000+
npm
3,698
NuGet
656
pip
3,315
Pub
11
RubyGems
882
Rust
832
Swift
35
Unreviewed advisories
All unreviewed
5,000+
290 advisories
Filter by severity
Gogs and Gitea SSRF Vulnerability
High
CVE-2018-15192
was published
for
code.gitea.io/gitea
(Go)
May 14, 2022
Jenkins Crowd 2 Integration Plugin server-side request forgery vulnerability
Moderate
CVE-2018-1000422
was published
for
org.jenkins-ci.plugins:crowd2
(Maven)
May 14, 2022
Server-side request forgery vulnerability in Jenkins Mesos Plugin
Moderate
CVE-2018-1000421
was published
for
org.jenkins-ci.plugins:mesos
(Maven)
May 14, 2022
Moodle SSRF Vulnerability
High
CVE-2019-6970
was published
for
moodle/moodle
(Composer)
May 14, 2022
phpMyAdmin SSRF in replication
High
CVE-2017-1000017
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Moodle SSRF Vulnerability
Moderate
CVE-2018-1042
was published
for
moodle/moodle
(Composer)
May 14, 2022
SSRF vulnerability due to missing permission check in Jenkins OctopusDeploy Plugin
Moderate
CVE-2019-1003027
was published
for
hudson.plugins.octopusdeploy:octopusdeploy
(Maven)
May 13, 2022
Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)
Moderate
CVE-2019-1003020
was published
for
org.jenkins-ci.plugins:kanboard
(Maven)
May 13, 2022
Jenkins Mattermost Notification Plugin vulnerable to SSRF
Moderate
CVE-2019-1003026
was published
for
org.jenkins-ci.plugins:mattermost
(Maven)
May 13, 2022
SSRF vulnerability due to missing permission check in Jenkins JMS Messaging Plugin
Moderate
CVE-2019-1003028
was published
for
org.jenkins-ci.plugins:jms-messaging
(Maven)
May 13, 2022
Moodle Blind SSRF Risk in /badges/mybackpack.php
Critical
CVE-2019-3809
was published
for
moodle/moodle
(Composer)
May 13, 2022
elFinder Server Side Request Forgery (SSRF)
High
CVE-2019-6257
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
Server-Side Request Forgery in Jenkins
Moderate
CVE-2018-1000067
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Server-Side Request Forgery in scout-browser
High
CVE-2022-1592
was published
for
scout-browser
(pip)
May 6, 2022
ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)
High
CVE-2022-25850
was published
for
github.com/hoppscotch/proxyscotch
(Go)
May 3, 2022
GeoServer allows SSRF via the option for setting a proxy host
High
CVE-2021-40822
was published
for
org.geoserver:gs-main
(Maven)
May 3, 2022
Server side request forgery in gibbon
Critical
CVE-2022-27311
was published
for
gibbon
(RubyGems)
Apr 26, 2022
Server-Side Request Forgery (SSRF) in Shopware
High
CVE-2022-24871
was published
for
shopware/core
(Composer)
Apr 22, 2022
Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector
High
CVE-2022-29153
was published
for
github.com/hashicorp/consul
(Go)
Apr 20, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
Server side request forgery in LiveHelperChat
High
CVE-2022-1213
was published
for
remdex/livehelperchat
(Composer)
Apr 6, 2022
Server side request forgery in C1 CMS
High
CVE-2022-24789
was published
for
C1CMS.Assemblies
(NuGet)
Mar 30, 2022
Server-Side Request Forgery in Apache Dubbo
Moderate
CVE-2021-25640
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
Server-Side Request Forgery in FUXA
High
CVE-2021-45851
was published
for
@frangoteam/fuxa
(npm)
Mar 17, 2022
Agent-to-controller security bypass in Jenkins Semantic Versioning Plugin
High
CVE-2022-27201
was published
for
org.jenkins-ci.plugins:semantic-versioning-plugin
(Maven)
Mar 16, 2022
ProTip!
Advisories are also available from the
GraphQL API