GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,064 advisories
Filter by severity
An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers...
Moderate
Unreviewed
CVE-2025-55624
was published
Aug 22, 2025
Focus for iOS would not respect a Content-Disposition header of type Attachment and would...
Moderate
Unreviewed
CVE-2025-55032
was published
Aug 19, 2025
The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request...
Moderate
Unreviewed
CVE-2025-7777
was published
Aug 20, 2025
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow...
Moderate
Unreviewed
CVE-2025-54144
was published
Aug 19, 2025
URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this...
Moderate
Unreviewed
CVE-2025-55706
was published
Aug 20, 2025
A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of...
Moderate
Unreviewed
CVE-2025-9193
was published
Aug 20, 2025
@astrojs/node's trailing slash handling causes open redirect issue
Moderate
CVE-2025-55207
was published
for
@astrojs/node
(npm)
Aug 15, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for...
Moderate
Unreviewed
CVE-2025-54681
was published
Aug 14, 2025
svg-sanitizer Bypasses Attribute Sanitization
Moderate
CVE-2025-55166
was published
for
enshrined/svg-sanitize
(Composer)
Aug 12, 2025
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2024-4445
was published
May 14, 2024
A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-8813
was published
Aug 10, 2025
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect...
Moderate
Unreviewed
CVE-2023-6812
was published
May 14, 2024
A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform...
Moderate
Unreviewed
CVE-2025-8737
was published
Aug 8, 2025
Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
Moderate
CVE-2023-35029
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Apache Tomcat Open Redirect vulnerability
Moderate
CVE-2023-41080
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 25, 2023
Astros's duplicate trailing slash feature leads to an open redirection security issue
Moderate
CVE-2025-54793
was published
for
astro
(npm)
Aug 7, 2025
An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack...
Moderate
Unreviewed
CVE-2024-34328
was published
Jul 31, 2025
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes
Moderate
CVE-2024-25609
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
Moderate
CVE-2024-25608
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Vulnerable to Open Redirect via Adaptive Media Administration Page
Moderate
CVE-2023-44308
was published
for
com.liferay:com.liferay.adaptive.media.web
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page
Moderate
CVE-2023-5190
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
@cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
CVE-2025-4143
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
Moderate
Unreviewed
CVE-2024-6149
was published
Jul 10, 2024
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to...
Moderate
Unreviewed
CVE-2024-5492
was published
Jul 10, 2024
A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker...
Moderate
Unreviewed
CVE-2025-44109
was published
Jul 23, 2025
ProTip!
Advisories are also available from the
GraphQL API