GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,516 advisories
Filter by severity
A malicious or compromised OData service could disclose sensitive authentication information and...
Moderate
Unreviewed
CVE-2026-66773
was published
Aug 11, 2026
SAP Approuter does not sufficiently validate certain token content under specific configurations....
High
Unreviewed
CVE-2026-58230
was published
Aug 11, 2026
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection...
Moderate
Unreviewed
CVE-2026-54214
was published
Aug 7, 2026
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
...
Moderate
Unreviewed
CVE-2026-54215
was published
Aug 7, 2026
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied...
Moderate
Unreviewed
CVE-2026-12071
was published
Aug 7, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene...
Low
Unreviewed
CVE-2026-66829
was published
Aug 6, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene...
Moderate
Unreviewed
CVE-2026-66370
was published
Aug 6, 2026
DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped...
Moderate
Unreviewed
CVE-2026-71240
was published
Aug 5, 2026
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and...
Moderate
Unreviewed
CVE-2026-14219
was published
Aug 4, 2026
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its...
Moderate
Unreviewed
CVE-2026-16296
was published
Aug 4, 2026
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown...
Low
Unreviewed
CVE-2026-18721
was published
Aug 4, 2026
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect...
High
Unreviewed
CVE-2026-69087
was published
Aug 3, 2026
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation...
High
Unreviewed
CVE-2025-71403
was published
Aug 1, 2026
core-geonetwork has an Open Redirect Bypass
Moderate
CVE-2026-53573
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 31, 2026
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows...
Low
Unreviewed
CVE-2026-67350
was published
Jul 31, 2026
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows...
High
Unreviewed
CVE-2026-10545
was published
Jul 30, 2026
Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows...
Moderate
Unreviewed
CVE-2026-66414
was published
Jul 30, 2026
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17912
was published
Jul 30, 2026
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote...
Moderate
Unreviewed
CVE-2026-18266
was published
Jul 29, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Critical
CVE-2026-54588
was published
for
poweradmin/poweradmin
(Composer)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an...
High
Unreviewed
CVE-2026-67178
was published
Jul 28, 2026
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect ...
Moderate
Unreviewed
CVE-2026-14171
was published
Jul 28, 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect...
Moderate
Unreviewed
CVE-2026-51564
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API