GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,911
Erlang
39
GitHub Actions
38
Go
2,569
Maven
5,000+
npm
4,245
NuGet
754
pip
4,006
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,210 advisories
Filter by severity
CVE-2025-54088 is an open-redirect vulnerability in Secure
Access prior to version 14.10....
Moderate
Unreviewed
CVE-2025-54088
was published
Oct 2, 2025
reflex-dev/reflex has an Open Redirect vulnerability
Low
CVE-2025-62379
was published
for
reflex
(pip)
Oct 15, 2025
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site (...
Low
Unreviewed
CVE-2025-54196
was published
Oct 15, 2025
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7...
Low
Unreviewed
CVE-2025-47890
was published
Oct 14, 2025
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin...
Moderate
Unreviewed
CVE-2025-11167
was published
Oct 11, 2025
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated...
Moderate
Unreviewed
CVE-2025-35059
was published
Oct 9, 2025
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This...
Moderate
Unreviewed
CVE-2025-40630
was published
May 16, 2025
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change...
Moderate
Unreviewed
CVE-2025-3027
was published
Mar 31, 2025
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An...
Moderate
Unreviewed
CVE-2025-11240
was published
Oct 2, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
Moderate
CVE-2024-1440
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util
(Maven)
Jun 2, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo...
Moderate
Unreviewed
CVE-2025-0608
was published
Oct 6, 2025
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the...
High
Unreviewed
CVE-2024-55017
was published
Sep 30, 2025
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
Moderate
Unreviewed
CVE-2025-57879
was published
Sep 29, 2025
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
Moderate
Unreviewed
CVE-2025-57872
was published
Sep 29, 2025
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may...
Moderate
Unreviewed
CVE-2025-57878
was published
Sep 29, 2025
lobe-chat has an Open Redirect
Moderate
CVE-2025-59426
was published
for
@lobehub/chat
(npm)
Sep 24, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
Moderate
Unreviewed
CVE-2025-58006
was published
Sep 22, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication...
Moderate
Unreviewed
CVE-2025-7702
was published
Sep 19, 2025
Mattermost Open Redirect vulnerability
Low
CVE-2025-9084
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Mattermost Open Redirect vulnerability
High
CVE-2025-9072
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
Moderate
CVE-2025-43795
was published
for
com.liferay:com.liferay.configuration.admin.web
(Maven)
Sep 12, 2025
A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the...
Moderate
Unreviewed
CVE-2025-10229
was published
Sep 11, 2025
TYPO3 CMS has an open‑redirect vulnerability
Moderate
CVE-2025-59013
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API