GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,236 advisories
Filter by severity
Central Dogma's Login Function Has an Open Redirect Vulnerability
Moderate
CVE-2025-11222
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-shiro
(Maven)
Dec 4, 2025
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20382
was published
Dec 3, 2025
Open redirect in the web server component of MiR Robot and Fleet software allows a remote...
Moderate
Unreviewed
CVE-2025-13819
was published
Dec 1, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube...
Low
Unreviewed
CVE-2025-66062
was published
Nov 21, 2025
Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0...
High
Unreviewed
CVE-2024-8527
was published
Nov 19, 2025
Backdrop CMS Host Header Injection vulnerability
Moderate
CVE-2025-63828
was published
for
backdrop/backdrop
(Composer)
Nov 18, 2025
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL...
Moderate
Unreviewed
CVE-2025-40545
was published
Nov 18, 2025
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a...
Moderate
Unreviewed
CVE-2024-13983
was published
Nov 14, 2025
A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance...
Moderate
Unreviewed
CVE-2025-20355
was published
Nov 13, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20378
was published
Nov 12, 2025
SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious...
Moderate
Unreviewed
CVE-2025-42924
was published
Nov 11, 2025
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker...
Moderate
Unreviewed
CVE-2025-42893
was published
Nov 11, 2025
An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web...
Moderate
Unreviewed
CVE-2025-63784
was published
Nov 7, 2025
A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that...
Moderate
Unreviewed
CVE-2025-12789
was published
Nov 7, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Liferay Portal is vulnerable to DNS rebinding attacks
Moderate
CVE-2025-62266
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 30, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Moderate
CVE-2025-64716
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Byaidu PDFMathTranslate vulnerable to open redirect
Low
CVE-2025-50736
was published
for
pdf2zh
(pip)
Oct 30, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
PrivateBin is missing HTML sanitization of attached filename in file size hint
Moderate
CVE-2025-62796
was published
for
privatebin/privatebin
(Composer)
Oct 28, 2025
Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
Moderate
CVE-2025-62253
was published
for
com.liferay:com.liferay.layout.admin.web
(Maven)
Oct 27, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
Moderate
Unreviewed
CVE-2025-62981
was published
Oct 27, 2025
Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker...
Moderate
Unreviewed
CVE-2025-10355
was published
Oct 23, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
High
Unreviewed
CVE-2025-60151
was published
Oct 22, 2025
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2025-61753
was published
Oct 21, 2025
ProTip!
Advisories are also available from the
GraphQL API