GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
66 advisories
Filter by severity
Symfony vulnerable to open redirect via browser-sanitized URLs
Low
CVE-2024-50345
was published
for
symfony/http-foundation
(Composer)
Nov 6, 2024
October System module has an Open Redirect for Administrator Accounts
Low
CVE-2024-24764
was published
for
october/system
(Composer)
Jun 26, 2024
Zendframework Remote Address Spoofing Vector in `Zend\Http\PhpEnvironment\RemoteAddress`
High
GHSA-xffp-6w68-4775
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
silverstripe/framework BackURL validation bypass with malformed URLs
High
GHSA-m5q3-mvcr-gc5m
was published
for
silverstripe/framework
(Composer)
May 27, 2024
Silverstripe External redirection risk in Security?ReturnURL
Moderate
GHSA-vp8p-c6xj-xpj7
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe X-Forwarded-Host request hostname injection
High
GHSA-25gq-jvx2-vg9x
was published
for
silverstripe/framework
(Composer)
May 23, 2024
OroPlatform Forced Redirect to External Website
Moderate
GHSA-3vhm-q4w3-rw8q
was published
for
oro/platform
(Composer)
May 20, 2024
OroCRM Forced Redirect to External Website
Moderate
GHSA-v8hp-239v-9367
was published
for
oro/crm
(Composer)
May 20, 2024
Drupal core Open Redirect vulnerability
Moderate
GHSA-wxfg-253g-m7r4
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal Anonymous Open Redirect
Moderate
GHSA-x6v2-xmrq-574j
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal External URL injection through URL aliases leading to Open Redirect
Moderate
GHSA-r67r-42wx-c8r7
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal core Open Redirect vulnerability
Moderate
GHSA-6gf6-24h2-66j4
was published
for
drupal/core
(Composer)
May 15, 2024
Drupal Anonymous Open Redirect
Moderate
GHSA-gfvf-2f25-f34r
was published
for
drupal/core
(Composer)
May 15, 2024
Drupal External URL injection through URL aliases leading to Open Redirect
Moderate
GHSA-7f4f-p7mq-p4fv
was published
for
drupal/core
(Composer)
May 15, 2024
Flarum's logout Route allows open redirects
Low
CVE-2024-21641
was published
for
flarum/core
(Composer)
Jan 5, 2024
Artesãos SEOTools Open Redirect vulnerability
Moderate
CVE-2020-36663
was published
for
artesaos/seotools
(Composer)
Jul 6, 2023
Artesãos SEOTools Open Redirect vulnerability
Moderate
CVE-2020-36664
was published
for
artesaos/seotools
(Composer)
Jul 6, 2023
Artesãos SEOTools Open Redirect vulnerability
Moderate
CVE-2020-36665
was published
for
artesaos/seotools
(Composer)
Jul 6, 2023
Open redirect vulnerability on CMSSecurity relogin screen
Moderate
CVE-2023-22729
was published
for
silverstripe/framework
(Composer)
Apr 26, 2023
Symbiote Seed Open Redirect vulnerability
Moderate
CVE-2017-20164
was published
for
symbiote/silverstripe-seed
(Composer)
Jan 7, 2023
Moodle Open redirect risk in mobile auto-login feature
Moderate
CVE-2022-35652
was published
for
moodle/moodle
(Composer)
Jul 26, 2022
Open Redirect in microweber
Moderate
CVE-2022-2252
was published
for
microweber/microweber
(Composer)
Jun 30, 2022
Drupal Core Open Redirect vulnerability
Moderate
CVE-2020-13662
was published
for
drupal/core
(Composer)
May 24, 2022
MediaWiki Open Redirect vulnerability
Moderate
CVE-2020-10959
was published
for
mediawiki/core
(Composer)
May 24, 2022
Knock Knock plugin Open redirection vulnerability
Moderate
CVE-2020-13486
was published
for
verbb/knock-knock
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API