GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
1,619 advisories
Filter by severity
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
Critical
CVE-2026-108261
was published
for
@tinacms/app
(npm)
Oct 9, 2026
Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL...
Unknown
Unreviewed
CVE-2026-79650
was published
Oct 9, 2026
AdonisJS: Unencoded route parameters can produce open redirects
Moderate
CVE-2026-107718
was published
for
@adonisjs/http-server
(npm)
Oct 8, 2026
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote,...
High
Unreviewed
CVE-2026-101152
was published
Oct 6, 2026
Insufficient validation of request in login flow could allow a remote, unauthenticated attacker...
Moderate
Unreviewed
CVE-2026-101151
was published
Oct 6, 2026
Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-106322
was published
Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit
Moderate
CVE-2026-105846
was published
for
@payloadcms/next
(npm)
Oct 6, 2026
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue...
Moderate
Unreviewed
CVE-2026-80327
was published
Oct 6, 2026
LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...
Moderate
Unreviewed
CVE-2026-105128
was published
Oct 4, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI...
Moderate
Unreviewed
CVE-2026-39600
was published
Oct 2, 2026
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly...
Moderate
Unreviewed
CVE-2026-97318
was published
Oct 2, 2026
A flaw was found in oauth-proxy. The application fails to properly validate the destination...
Moderate
Unreviewed
CVE-2026-83589
was published
Oct 1, 2026
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
High
CVE-2026-101907
was published
for
axios
(npm)
Sep 30, 2026
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect...
Low
Unreviewed
CVE-2026-88791
was published
Sep 30, 2026
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation...
Moderate
Unreviewed
CVE-2026-103048
was published
Sep 30, 2026
Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint...
Moderate
Unreviewed
CVE-2026-53989
was published
Sep 29, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL...
Moderate
Unreviewed
CVE-2026-73599
was published
Sep 29, 2026
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
Moderate
Unreviewed
CVE-2026-76720
was published
Sep 29, 2026
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the...
Critical
Unreviewed
CVE-2026-101090
was published
Sep 27, 2026
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes...
Moderate
Unreviewed
CVE-2026-100523
was published
Sep 26, 2026
A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected...
Low
Unreviewed
CVE-2026-97325
was published
Sep 24, 2026
A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect...
Low
Unreviewed
CVE-2026-96892
was published
Sep 24, 2026
A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects...
Low
Unreviewed
CVE-2026-96773
was published
Sep 24, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in...
Moderate
Unreviewed
CVE-2026-18505
was published
Sep 23, 2026
URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co....
Moderate
Unreviewed
CVE-2026-80444
was published
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API