GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,504 advisories
Filter by severity
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation...
High
Unreviewed
CVE-2025-71403
was published
Aug 1, 2026
core-geonetwork has an Open Redirect Bypass
Moderate
CVE-2026-53573
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 31, 2026
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows...
Low
Unreviewed
CVE-2026-67350
was published
Jul 31, 2026
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows...
High
Unreviewed
CVE-2026-10545
was published
Jul 30, 2026
Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows...
Moderate
Unreviewed
CVE-2026-66414
was published
Jul 30, 2026
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17912
was published
Jul 30, 2026
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote...
Moderate
Unreviewed
CVE-2026-18266
was published
Jul 29, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Critical
CVE-2026-54588
was published
for
poweradmin/poweradmin
(Composer)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an...
High
Unreviewed
CVE-2026-67178
was published
Jul 28, 2026
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect ...
Moderate
Unreviewed
CVE-2026-14171
was published
Jul 28, 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect...
Moderate
Unreviewed
CVE-2026-51564
was published
Jul 28, 2026
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied...
Moderate
Unreviewed
CVE-2026-14236
was published
Jul 27, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
Moderate
GHSA-38hq-7x33-php4
was published
for
@backstage/plugin-auth-backend
(npm)
Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Moderate
CVE-2026-53669
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Open redirect leading to XSS
Moderate
CVE-2026-53668
was published
for
react-router
(npm)
Jul 23, 2026
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2026-61254
was published
Jul 22, 2026
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60467
was published
Jul 22, 2026
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are...
Moderate
Unreviewed
CVE-2026-47045
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2026-47048
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2026-47051
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47026
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47015
was published
Jul 22, 2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager...
High
Unreviewed
CVE-2026-46998
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API