GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,056 advisories
        Filter by severity
        
      
      
    
                    
                      There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39097
                      
                      was published
                      Aug 26, 2024 
                    
                  
                    
                      By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62266
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2091
                      
                      was published
                      Jun 16, 2025 
                    
                  
                    
                      PrivateBin is missing HTML sanitization of attached filename in file size hint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62796
                      
                      was published
                        for
                        
                          privatebin/privatebin
                        
                        (Composer)
                      Oct 28, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62253
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.layout.admin.web
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-49706
                      
                      was published
                      Apr 14, 2025 
                    
                  
                    
                      URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62981
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10355
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component:...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61753
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2012-0518
                      
                      was published
                      May 4, 2022 
                    
                  
                    
                      Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-38000
                      
                      was published
                      Nov 24, 2021 
                    
                  
                    
                      Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62595
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Oct 21, 2025 
                    
                  
                    
                      CVE-2025-54088 is an open-redirect vulnerability in Secure
Access prior to version 14.10....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54088
                      
                      was published
                      Oct 2, 2025 
                    
                  
                    
                      chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
                    
                      
  Moderate
                    
                
                      
                        GHSA-vrw8-fxc6-2r93
                      
                      was published
                        for
                        
                          github.com/go-chi/chi/v5
                        
                        (Go)
                      Jun 20, 2025 
                    
                  
                    
                      The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11167
                      
                      was published
                      Oct 11, 2025 
                    
                  
                    
                      Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-35059
                      
                      was published
                      Oct 9, 2025 
                    
                  
                    
                      Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-40630
                      
                      was published
                      May 16, 2025 
                    
                  
                    
                      The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3027
                      
                      was published
                      Mar 31, 2025 
                    
                  
                    
                      An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11240
                      
                      was published
                      Oct 2, 2025 
                    
                  
                    
                      WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-1440
                      
                      was published
                        for
                        
                          org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util
                        
                        (Maven)
                      Jun 2, 2025 
                    
                  
                    
                      URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0608
                      
                      was published
                      Oct 6, 2025 
                    
                  
                    
                      There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57879
                      
                      was published
                      Sep 29, 2025 
                    
                  
                    
                      There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57872
                      
                      was published
                      Sep 29, 2025 
                    
                  
                    
                      There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57878
                      
                      was published
                      Sep 29, 2025 
                    
                  
                    
                      lobe-chat has an Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59426
                      
                      was published
                        for
                        
                          @lobehub/chat
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API