GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
371 advisories
Filter by severity
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of...
Critical
Unreviewed
CVE-2026-77012
was published
Aug 29, 2026
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate...
Critical
Unreviewed
CVE-2026-16947
was published
Aug 29, 2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of...
Critical
Unreviewed
CVE-2026-75340
was published
Aug 27, 2026
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService...
Critical
Unreviewed
CVE-2026-75332
was published
Aug 27, 2026
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability...
Critical
Unreviewed
CVE-2026-76193
was published
Aug 25, 2026
Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1...
Critical
Unreviewed
CVE-2026-55976
was published
Aug 25, 2026
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF...
Critical
Unreviewed
CVE-2026-78003
was published
Aug 22, 2026
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-69502
was published
Aug 21, 2026
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module,...
Critical
Unreviewed
CVE-2026-59085
was published
Aug 21, 2026
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to...
Critical
Unreviewed
CVE-2026-69851
was published
Aug 21, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker...
Critical
Unreviewed
CVE-2026-65801
was published
Aug 21, 2026
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes....
Critical
Unreviewed
CVE-2026-66794
was published
Aug 19, 2026
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth()...
Critical
Unreviewed
CVE-2026-12564
was published
Aug 18, 2026
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache...
Critical
Unreviewed
CVE-2026-34884
was published
Aug 18, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Critical
CVE-2026-64849
was published
for
mlflow
(pip)
Aug 17, 2026
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2026-50775
was published
Aug 17, 2026
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue...
Critical
Unreviewed
CVE-2026-69223
was published
Aug 11, 2026
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Critical
CVE-2026-73080
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 11, 2026
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound...
Critical
Unreviewed
CVE-2026-19516
was published
Aug 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker...
Critical
Unreviewed
CVE-2026-70332
was published
Aug 7, 2026
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery...
Critical
Unreviewed
CVE-2026-53983
was published
Aug 7, 2026
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier...
Critical
Unreviewed
CVE-2026-15732
was published
Aug 7, 2026
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources...
Critical
Unreviewed
CVE-2026-12605
was published
Aug 6, 2026
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability...
Critical
Unreviewed
CVE-2026-48331
was published
Aug 4, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API