GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,950 advisories
Filter by severity
The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery...
High
Unreviewed
CVE-2026-3478
was published
Mar 21, 2026
The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2026-1648
was published
Mar 21, 2026
The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Moderate
Unreviewed
CVE-2026-2290
was published
Mar 21, 2026
The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2026-1313
was published
Mar 21, 2026
The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request...
High
Unreviewed
CVE-2026-4302
was published
Mar 21, 2026
AVideo has Unauthenticated SSRF via plugin/Live/test.php
Critical
CVE-2026-33502
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled
Moderate
GHSA-pgx6-7jcq-2qff
was published
for
@pdfme/common
(npm)
Mar 20, 2026
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
High
CVE-2026-33480
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-32169
was published
Mar 19, 2026
Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized...
High
Unreviewed
CVE-2026-26137
was published
Mar 19, 2026
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2026-26120
was published
Mar 19, 2026
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-26138
was published
Mar 19, 2026
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-26139
was published
Mar 19, 2026
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
Critical
CVE-2026-33351
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
league/commonmark has an embed extension allowed_domains bypass
Moderate
CVE-2026-33347
was published
for
league/commonmark
(Composer)
Mar 19, 2026
AVideo Affected by SSRF in BulkEmbed Thumbnail Fetch Allows Reading Internal Network Resources
Moderate
CVE-2026-33294
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request...
Moderate
Unreviewed
CVE-2025-71258
was published
Mar 19, 2026
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request...
Moderate
Unreviewed
CVE-2025-71259
was published
Mar 19, 2026
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
Moderate
CVE-2026-33237
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Duplicate Advisory: web_search citation redirect SSRF via private-network-allowing policy
Moderate
GHSA-44c9-4rg5-qjgq
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
High
CVE-2026-33226
was published
for
budibase
(npm)
Mar 18, 2026
PinchTab has a Blind SSRF via browser-side redirect bypass in /download URL validation
Moderate
CVE-2026-33081
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 18, 2026
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
Moderate
CVE-2026-33060
was published
for
@aborruso/ckan-mcp-server
(npm)
Mar 18, 2026
A flaw was identified in Keycloak, an identity and access management solution, where it...
Moderate
Unreviewed
CVE-2026-4366
was published
Mar 18, 2026
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
High
CVE-2026-33039
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
ProTip!
Advisories are also available from the
GraphQL API