GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
1,751 advisories
Filter by severity
Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in...
High
Unreviewed
CVE-2026-22219
was published
Jan 20, 2026
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the...
Moderate
Unreviewed
CVE-2026-1062
was published
Jan 17, 2026
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Low
Unreviewed
CVE-2026-0682
was published
Jan 17, 2026
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request...
Moderate
Unreviewed
CVE-2025-14793
was published
Jan 16, 2026
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to...
Moderate
Unreviewed
CVE-2026-23768
was published
Jan 16, 2026
Umbraco CMS contains a server-side request forgery vulnerability
Moderate
CVE-2021-47776
was published
for
UmbracoCms
(NuGet)
Jan 15, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0...
Moderate
Unreviewed
CVE-2026-0600
was published
Jan 15, 2026
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918...
High
Unreviewed
CVE-2026-0532
was published
Jan 14, 2026
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2025-14613
was published
Jan 14, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Moderate
CVE-2026-22772
was published
for
github.com/sigstore/fulcio
(Go)
Jan 13, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-20958
was published
Jan 13, 2026
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet...
Low
Unreviewed
CVE-2025-67685
was published
Jan 13, 2026
Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated...
Moderate
Unreviewed
CVE-2025-65784
was published
Jan 13, 2026
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request...
Moderate
Unreviewed
CVE-2025-13393
was published
Jan 10, 2026
Ghost has SSRF via External Media Inliner
Moderate
CVE-2026-22597
was published
for
ghost
(npm)
Jan 8, 2026
picklescan has Arbitrary file read using `io.FileIO`
High
GHSA-9726-w42j-3qjr
was published
for
picklescan
(pip)
Jan 8, 2026
Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows...
Critical
Unreviewed
CVE-2025-22726
was published
Jan 8, 2026
Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery...
Moderate
Unreviewed
CVE-2019-25290
was published
Jan 8, 2026
Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources
Moderate
CVE-2026-21885
was published
for
miniflux.app/v2
(Go)
Jan 7, 2026
Server-Side Request Forgery (SSRF) vulnerability in minnur External Media allows Server Side...
Moderate
Unreviewed
CVE-2025-49335
was published
Jan 7, 2026
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is...
Moderate
Unreviewed
CVE-2026-0649
was published
Jan 7, 2026
Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2026-21859
was published
for
github.com/axllent/mailpit
(Go)
Jan 6, 2026
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery...
Moderate
Unreviewed
CVE-2025-14438
was published
Jan 6, 2026
ProTip!
Advisories are also available from the
GraphQL API