Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,619 advisories

Loading
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment Critical
CVE-2026-108261 was published for @tinacms/app (npm) Oct 9, 2026
sondt99 Credited to sondt99
AdonisJS: Unencoded route parameters can produce open redirects Moderate
CVE-2026-107718 was published for @adonisjs/http-server (npm) Oct 8, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Payload: Untrusted redirect URL parameter exploit Moderate
CVE-2026-105846 was published for @payloadcms/next (npm) Oct 6, 2026
kullai-secasure Credited to kullai-secasure and yuvraj-secasure yuvraj-secasure yuvraj-secasure
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF High
CVE-2026-101907 was published for axios (npm) Sep 30, 2026
mcdubhghlas Credited to mcdubhghlas
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. Moderate Unreviewed
CVE-2026-76720 was published Sep 29, 2026
ProTip! Advisories are also available from the GraphQL API