GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,777 advisories
Filter by severity
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function...
Low
Unreviewed
CVE-2026-18856
was published
Aug 5, 2026
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows...
Moderate
Unreviewed
CVE-2026-70620
was published
Aug 5, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Moderate
CVE-2026-70480
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
High
CVE-2026-70479
was published
for
open-webui
(pip)
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47618
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation...
High
Unreviewed
CVE-2026-47613
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request...
High
Unreviewed
CVE-2026-47614
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47616
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request...
High
Unreviewed
CVE-2026-47615
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47617
was published
Aug 4, 2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability...
Low
Unreviewed
CVE-2026-18775
was published
Aug 4, 2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function...
Low
Unreviewed
CVE-2026-18774
was published
Aug 4, 2026
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe...
Moderate
Unreviewed
CVE-2026-14939
was published
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate...
Moderate
Unreviewed
CVE-2026-16536
was published
Aug 4, 2026
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making...
Moderate
Unreviewed
CVE-2026-10526
was published
Aug 4, 2026
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when...
Moderate
Unreviewed
CVE-2026-70367
was published
Aug 4, 2026
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability...
Critical
Unreviewed
CVE-2026-48331
was published
Aug 4, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized...
Moderate
Unreviewed
CVE-2026-66325
was published
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API