GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,339 advisories
Filter by severity
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
Moderate
Unreviewed
CVE-2025-62981
was published
Oct 27, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms...
High
Unreviewed
CVE-2025-60151
was published
Oct 22, 2025
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to...
High
Unreviewed
CVE-2026-0712
was published
Jan 15, 2026
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path...
High
Unreviewed
CVE-2026-22638
was published
Jan 15, 2026
An open redirect vulnerability has been identified in Grafana OSS organization switching...
Moderate
Unreviewed
CVE-2026-22642
was published
Jan 15, 2026
Improper validation of a login parameter may allow attackers to redirect users to malicious...
Moderate
Unreviewed
CVE-2026-22912
was published
Jan 15, 2026
chi has an open redirect vulnerability in the RedirectSlashes middleware
Moderate
GHSA-mqqf-5wvp-8fh8
was published
for
github.com/go-chi/chi
(Go)
Jan 14, 2026
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in...
Moderate
Unreviewed
CVE-2026-0513
was published
Jan 13, 2026
Mattermost Server mishandles redirect denial action
Moderate
CVE-2017-18897
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
React Router has unexpected external redirect via untrusted paths
Moderate
CVE-2025-68470
was published
for
react-router
(npm)
Jan 8, 2026
Directus has open redirect in SAML
Moderate
CVE-2026-22032
was published
for
@directus/api
(npm)
Jan 6, 2026
V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that...
Moderate
Unreviewed
CVE-2019-25282
was published
Jan 8, 2026
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web...
Low
Unreviewed
CVE-2025-55254
was published
Dec 17, 2025
Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the ...
Moderate
Unreviewed
CVE-2020-36912
was published
Jan 6, 2026
Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml'...
Moderate
Unreviewed
CVE-2025-15112
was published
Dec 31, 2025
A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the...
Moderate
Unreviewed
CVE-2025-15258
was published
Dec 30, 2025
A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The...
Moderate
Unreviewed
CVE-2025-15241
was published
Dec 30, 2025
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Moderate
Unreviewed
CVE-2025-55060
was published
Dec 29, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to...
Moderate
Unreviewed
CVE-2025-60935
was published
Dec 24, 2025
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Moderate
CVE-2025-50181
was published
for
urllib3
(pip)
Jun 18, 2025
urllib3 does not control redirects in browsers and Node.js
Moderate
CVE-2025-50182
was published
for
urllib3
(pip)
Jun 18, 2025
Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
Moderate
CVE-2025-43795
was published
for
com.liferay:com.liferay.configuration.admin.web
(Maven)
Sep 12, 2025
Express.js Open Redirect in malformed URLs
Moderate
CVE-2024-29041
was published
for
express
(npm)
Mar 25, 2024
AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation...
Moderate
Unreviewed
CVE-2025-34439
was published
Dec 17, 2025
ProTip!
Advisories are also available from the
GraphQL API