GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,491 advisories
Filter by severity
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied...
Moderate
Unreviewed
CVE-2026-14236
was published
Jul 27, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
Moderate
GHSA-38hq-7x33-php4
was published
for
@backstage/plugin-auth-backend
(npm)
Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Moderate
CVE-2026-53669
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Open redirect leading to XSS
Moderate
CVE-2026-53668
was published
for
react-router
(npm)
Jul 23, 2026
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2026-61254
was published
Jul 22, 2026
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component:...
High
Unreviewed
CVE-2026-60467
was published
Jul 22, 2026
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are...
Moderate
Unreviewed
CVE-2026-47045
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2026-47048
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2026-47051
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47026
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2026-47015
was published
Jul 22, 2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager...
High
Unreviewed
CVE-2026-46998
was published
Jul 22, 2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager...
Moderate
Unreviewed
CVE-2026-47002
was published
Jul 22, 2026
URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc....
Moderate
Unreviewed
CVE-2026-8284
was published
Jul 21, 2026
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core...
Moderate
Unreviewed
CVE-2026-16336
was published
Jul 21, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback...
Moderate
Unreviewed
CVE-2026-63768
was published
Jul 20, 2026
The Joomla extension Hikashop is vulnerable to an open redirect.
Moderate
Unreviewed
CVE-2026-61901
was published
Jul 20, 2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9...
Low
Unreviewed
CVE-2026-7364
was published
Jul 17, 2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to...
Moderate
Unreviewed
CVE-2026-15093
was published
Jul 17, 2026
An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation...
Moderate
Unreviewed
CVE-2026-12379
was published
Jul 16, 2026
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client...
Critical
Unreviewed
CVE-2026-61451
was published
Jul 15, 2026
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could...
Moderate
Unreviewed
CVE-2026-48000
was published
Jul 14, 2026
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated...
Moderate
Unreviewed
CVE-2026-14902
was published
Jul 14, 2026
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow...
High
Unreviewed
CVE-2026-44745
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API