GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
Authentication bypass in @sap/approuter
High
CVE-2025-24876
was published
for
@sap/approuter
(npm)
Feb 11, 2025
The User Account and Authentication service (UAA) for SAP HANA extended application services,...
High
Unreviewed
CVE-2025-24868
was published
Feb 11, 2025
The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to...
High
Unreviewed
CVE-2024-46481
was published
Jan 13, 2025
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker...
High
Unreviewed
CVE-2023-25734
was published
Jun 2, 2023
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
High
CVE-2024-56734
was published
for
better-auth
(npm)
Dec 30, 2024
Duplicate Advisory: Keycloak Open Redirect vulnerability
High
GHSA-vvf8-2h68-9475
was published
for
org.keycloak:keycloak-services
(Maven)
Sep 19, 2024
•
withdrawn
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6...
High
Unreviewed
CVE-2024-11274
was published
Dec 12, 2024
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
High
CVE-2024-34065
was published
for
@strapi/plugin-users-permissions
(npm)
Jun 12, 2024
Unsafe handling of user-specified cookies in treq
High
CVE-2022-23607
was published
for
treq
(pip)
Feb 1, 2022
HAPI FHIR XML External Entity (XXE) vulnerability
High
CVE-2024-51132
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Nov 5, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100...
High
Unreviewed
CVE-2024-43683
was published
Oct 4, 2024
VMware SD-WAN Orchestrator contains an open redirect vulnerability.
A malicious actor may be...
High
Unreviewed
CVE-2024-22248
was published
Apr 2, 2024
Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites...
High
Unreviewed
CVE-2024-2465
was published
Mar 21, 2024
Drupal has open redirect vulnerability in the Overlay module
High
CVE-2013-6389
was published
for
drupal/drupal
(Composer)
May 17, 2022
rdiffweb vulnerable to Open Redirect
High
CVE-2022-4720
was published
for
rdiffweb
(pip)
Dec 27, 2022
URL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportal
High
CVE-2021-32806
was published
for
Products.isurlinportal
(pip)
Aug 5, 2021
Plone Open Redirection vulnerability via next parameter
High
CVE-2013-4200
was published
for
Plone
(pip)
May 14, 2022
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8,...
High
Unreviewed
CVE-2023-3922
was published
Sep 29, 2023
Open redirect via transitional IPv6 addresses on dual-stack networks
High
CVE-2021-21392
was published
for
matrix-synapse
(pip)
Apr 13, 2021
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect...
High
Unreviewed
CVE-2024-46331
was published
Sep 27, 2024
A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the...
High
Unreviewed
CVE-2024-45979
was published
Sep 26, 2024
A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the...
High
Unreviewed
CVE-2024-45981
was published
Sep 26, 2024
flask-oidc Open Redirect vulnerability
High
CVE-2016-1000001
was published
for
flask-oidc
(pip)
May 17, 2022
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to,...
High
Unreviewed
CVE-2024-8761
was published
Sep 17, 2024
ProTip!
Advisories are also available from the
GraphQL API