GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,338 advisories
Filter by severity
JupyterHub has an Open Redirect Vulnerability
Moderate
CVE-2026-33709
was published
for
jupyterhub
(pip)
Apr 3, 2026
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a...
Moderate
Unreviewed
CVE-2025-61166
was published
Apr 6, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash...
High
Unreviewed
CVE-2018-25245
was published
Apr 4, 2026
Directus: Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Moderate
CVE-2026-35410
was published
for
directus
(npm)
Apr 4, 2026
Directus: Open Redirect in Admin 2FA Setup Page
Moderate
CVE-2026-35411
was published
for
directus
(npm)
Apr 4, 2026
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
High
CVE-2026-3872
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow
Moderate
CVE-2026-34083
was published
for
signalk-server
(npm)
Apr 3, 2026
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2026-5467
was published
Apr 3, 2026
Open redirect vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows...
Moderate
Unreviewed
CVE-2011-1594
was published
May 17, 2022
The issue was addressed with improved input validation. This issue is fixed in Safari 18.4,...
High
Unreviewed
CVE-2025-24180
was published
Apr 1, 2025
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
Low
Unreviewed
CVE-2026-2475
was published
Apr 1, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Sunshine Sunshine Photo...
Moderate
Unreviewed
CVE-2024-50463
was published
Oct 28, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple...
Moderate
Unreviewed
CVE-2024-49682
was published
Oct 24, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in QuomodoSoft ElementsReady...
Moderate
Unreviewed
CVE-2024-47353
was published
Oct 11, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple...
Moderate
Unreviewed
CVE-2024-47354
was published
Oct 10, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime...
Moderate
Unreviewed
CVE-2024-47648
was published
Oct 10, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payflex Payflex Payment...
Moderate
Unreviewed
CVE-2024-47646
was published
Oct 5, 2024
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The...
Moderate
Unreviewed
CVE-2024-58342
was published
Apr 1, 2026
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to...
Moderate
Unreviewed
CVE-2026-4799
was published
Mar 31, 2026
Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
Moderate
CVE-2026-33885
was published
for
statamic/cms
(Composer)
Mar 26, 2026
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR
Moderate
CVE-2026-33397
was published
for
@angular/ssr
(npm)
Mar 19, 2026
n8n: Authenticated XSS and Open Redirect via Form Node
Moderate
GHSA-w673-8fjw-457c
was published
for
n8n
(npm)
Mar 27, 2026
AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
Low
CVE-2026-33296
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops...
Moderate
Unreviewed
CVE-2026-1166
was published
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API