GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,167
Maven
5,000+
npm
3,830
NuGet
696
pip
3,508
Pub
12
RubyGems
910
Rust
906
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,062 advisories
Filter by severity
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE...
High
Unreviewed
CVE-2024-6377
was published
Aug 20, 2024
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in...
High
Unreviewed
CVE-2024-6379
was published
Aug 20, 2024
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition...
High
Unreviewed
CVE-2019-6781
was published
May 24, 2022
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon...
Moderate
Unreviewed
CVE-2024-43280
was published
Aug 19, 2024
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal...
Moderate
Unreviewed
CVE-2024-43236
was published
Aug 19, 2024
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by...
Moderate
Unreviewed
CVE-2024-7902
was published
Aug 18, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
High
Unreviewed
CVE-2024-38211
was published
Aug 13, 2024
Khoj Open Redirect Vulnerability in Login Page
Moderate
GHSA-564j-v29w-rqr6
was published
for
khoj-assistant
(pip)
Jul 8, 2024
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
Moderate
Unreviewed
CVE-2024-4882
was published
Jul 8, 2024
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before...
Moderate
Unreviewed
CVE-2024-0953
was published
Feb 5, 2024
lorawan-stack Open Redirect vulnerability
Moderate
CVE-2023-26494
was published
for
go.thethings.network/lorawan-stack/v3
(Go)
Aug 5, 2024
MobSF vulnerable to Open Redirect in Login Redirect
Moderate
CVE-2024-41955
was published
for
mobsf
(pip)
Jul 31, 2024
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via...
Moderate
Unreviewed
CVE-2024-37830
was published
Jul 9, 2024
When a network error occurred during page load, the prior content could have remained in view...
High
Unreviewed
CVE-2024-4773
was published
May 14, 2024
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to...
Moderate
Unreviewed
CVE-2024-5492
was published
Jul 10, 2024
IdentityServer Open Redirect vulnerability
Moderate
GHSA-55p7-v223-x366
was published
for
IdentityServer4
(NuGet)
Jul 31, 2024
IdentityServer Open Redirect vulnerability
Moderate
CVE-2024-39694
was published
for
Duende.IdentityServer
(NuGet)
Jul 31, 2024
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0...
Moderate
Unreviewed
CVE-2021-38000
was published
Nov 24, 2021
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an...
Moderate
Unreviewed
CVE-2024-20400
was published
Jul 17, 2024
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page...
Moderate
Unreviewed
CVE-2024-6289
was published
Jul 15, 2024
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all...
High
Unreviewed
CVE-2024-3597
was published
Jun 20, 2024
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle...
Moderate
Unreviewed
CVE-2012-0518
was published
May 4, 2022
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS...
Low
Unreviewed
CVE-2024-37234
was published
Jul 6, 2024
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to...
Moderate
Unreviewed
CVE-2024-4704
was published
Jun 27, 2024
An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a...
High
Unreviewed
CVE-2024-26504
was published
May 1, 2024
ProTip!
Advisories are also available from the
GraphQL API