Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,491 advisories

Loading
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass Moderate
GHSA-38hq-7x33-php4 was published for @backstage/plugin-auth-backend (npm) Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) Moderate
CVE-2026-53669 was published for react-router (npm) Jul 23, 2026
outring Credited to outring
React Router: Open redirect leading to XSS Moderate
CVE-2026-53668 was published for react-router (npm) Jul 23, 2026
SouadSEBAA Credited to SouadSEBAA
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite ... Moderate Unreviewed
CVE-2026-61254 was published Jul 22, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
alanturing881 Credited to alanturing881
The Joomla extension Hikashop is vulnerable to an open redirect. Moderate Unreviewed
CVE-2026-61901 was published Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API