GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,513
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
147 advisories
Filter by severity
SAP Approuter does not sufficiently validate certain token content under specific configurations....
High
Unreviewed
CVE-2026-58230
was published
Aug 11, 2026
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect...
High
Unreviewed
CVE-2026-69087
was published
Aug 3, 2026
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation...
High
Unreviewed
CVE-2025-71403
was published
Aug 1, 2026
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows...
High
Unreviewed
CVE-2026-10545
was published
Jul 30, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an...
High
Unreviewed
CVE-2026-67178
was published
Jul 28, 2026
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60467
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47026
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47015
was published
Jul 22, 2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager...
High
Unreviewed
CVE-2026-46998
was published
Jul 22, 2026
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow...
High
Unreviewed
CVE-2026-44745
was published
Jul 14, 2026
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
High
GHSA-86j7-9j95-vpqj
was published
for
better-auth
(npm)
Jul 7, 2026
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
High
CVE-2026-55431
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat...
High
Unreviewed
CVE-2026-47645
was published
Jun 19, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-46796
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-46806
was published
Jun 17, 2026
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). ...
High
Unreviewed
CVE-2026-35302
was published
Jun 17, 2026
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). ...
High
Unreviewed
CVE-2026-35258
was published
Jun 17, 2026
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). ...
High
Unreviewed
CVE-2026-35259
was published
Jun 17, 2026
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
High
CVE-2026-40961
was published
for
apache-airflow
(pip)
Jun 1, 2026
Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An...
High
Unreviewed
CVE-2025-26483
was published
May 26, 2026
Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak
High
CVE-2026-7504
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
High
CVE-2026-43941
was published
for
electerm
(npm)
May 8, 2026
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
High
GHSA-p64j-f4x9-wq66
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API