GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,290 advisories
Filter by severity
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft...
Moderate
Unreviewed
CVE-2026-24328
was published
Feb 10, 2026
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high...
High
Unreviewed
CVE-2026-0508
was published
Feb 10, 2026
The BSP applications allow an unauthenticated user to inject malicious script content via user...
Moderate
Unreviewed
CVE-2026-24323
was published
Feb 10, 2026
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an...
Moderate
Unreviewed
CVE-2026-0484
was published
Feb 10, 2026
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
This...
Moderate
Unreviewed
CVE-2025-66596
was published
Feb 9, 2026
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the...
Moderate
Unreviewed
CVE-2026-2153
was published
Feb 8, 2026
client-certificate-auth Vulnerable to Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect
Moderate
CVE-2026-25651
was published
for
client-certificate-auth
(npm)
Feb 6, 2026
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function...
Moderate
Unreviewed
CVE-2026-1970
was published
Feb 6, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
web2py has an Open Redirect Vulnerability
Moderate
CVE-2026-25198
was published
for
web2py
(pip)
Feb 5, 2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2026-20123
was published
Feb 4, 2026
Qwik City Open Redirect via fixTrailingSlash
Low
CVE-2026-25149
was published
for
@builder.io/qwik-city
(npm)
Feb 3, 2026
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
High
CVE-2026-24052
was published
for
@anthropic-ai/claude-code
(npm)
Feb 3, 2026
Moodle Open Redirect vulnerability
Low
CVE-2025-67852
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
WireGuard Portal v2 has Open Redirect Vulnerability in OAuth Authentication Flow
Moderate
GHSA-grh9-37g7-53mj
was published
for
github.com/h44z/wg-portal
(Go)
Feb 2, 2026
NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter
Moderate
CVE-2026-24768
was published
for
nocodb
(npm)
Jan 28, 2026
A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600....
Moderate
Unreviewed
CVE-2026-1406
was published
Jan 25, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
An open redirect vulnerability has been identified in Grafana OSS organization switching...
Moderate
Unreviewed
CVE-2026-22642
was published
Jan 15, 2026
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path...
High
Unreviewed
CVE-2026-22638
was published
Jan 15, 2026
Improper validation of a login parameter may allow attackers to redirect users to malicious...
Moderate
Unreviewed
CVE-2026-22912
was published
Jan 15, 2026
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to...
High
Unreviewed
CVE-2026-0712
was published
Jan 15, 2026
chi has an open redirect vulnerability in the RedirectSlashes middleware
Moderate
GHSA-mqqf-5wvp-8fh8
was published
for
github.com/go-chi/chi
(Go)
Jan 14, 2026
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in...
Moderate
Unreviewed
CVE-2026-0513
was published
Jan 13, 2026
React Router has unexpected external redirect via untrusted paths
Moderate
CVE-2025-68470
was published
for
react-router
(npm)
Jan 8, 2026
ProTip!
Advisories are also available from the
GraphQL API