GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,417
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
Jenkins OpenShift Login Plugin vulnerable to Open Redirect
Moderate
CVE-2023-37947
was published
for
org.openshift.jenkins:openshift-login
(Maven)
Jul 12, 2023
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
Moderate
CVE-2023-32068
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
May 15, 2023
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
Moderate
CVE-2023-29204
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 12, 2023
lambdaisland/uri `authority-regex` returns the wrong authority
Moderate
CVE-2023-28628
was published
for
lambdaisland:uri
(Maven)
Mar 27, 2023
Open redirect vulnerability in Jenkins OpenID Plugin
Moderate
CVE-2023-24445
was published
for
org.jenkins-ci.plugins:openid
(Maven)
Jan 26, 2023
Apache Helix UI vulnerable to Open Redirect
Moderate
CVE-2022-47500
was published
for
org.apache.helix:helix
(Maven)
Dec 19, 2022
Jenkins Google Login Plugin Open Redirect vulnerability
Moderate
CVE-2022-46683
was published
for
org.jenkins-ci.plugins:google-login
(Maven)
Dec 12, 2022
Authenticated OpenRedirect Vulnerability
Moderate
CVE-2022-41965
was published
for
org.opencastproject:opencast-common
(Maven)
Nov 30, 2022
Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented
Moderate
CVE-2022-28977
was published
for
com.liferay.portal:com.liferay.util.java
(Maven)
Sep 23, 2022
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11
High
CVE-2022-31193
was published
for
org.dspace:dspace-jspui
(Maven)
Aug 6, 2022
Server-side request forgery in Apache Dubbo
Moderate
CVE-2022-24969
was published
for
com.alibaba:dubbo
(Maven)
Jun 10, 2022
Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs
Moderate
CVE-2021-33331
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Open redirect vulnerability in Jenkins CAS Plugin
Moderate
CVE-2021-21673
was published
for
org.jenkins-ci.plugins:cas-plugin
(Maven)
May 24, 2022
Keycloak vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-10770
was published
for
org.keycloak:keycloak-core
(Maven)
May 24, 2022
Athenz vulnerable to Open Redirect
Moderate
CVE-2019-6035
was published
for
com.yahoo.athenz:athenz
(Maven)
May 24, 2022
Jenkins Gitlab Authentication Plugin Open Redirect vulnerability
Moderate
CVE-2019-10372
was published
for
org.jenkins-ci.plugins:gitlab-oauth
(Maven)
May 24, 2022
JBoss KeyCloak Open Redirect
Moderate
CVE-2014-3652
was published
for
org.keycloak:keycloak-services
(Maven)
May 17, 2022
Dojo Open Redirect vulnerability
Moderate
CVE-2010-2274
was published
for
org.dojotoolkit:dojo
(Maven)
May 17, 2022
Apache Sling Auth Core bundle vulnerable to Open Redirection
Moderate
CVE-2013-4390
was published
for
org.apache.sling:org.apache.sling.auth.core
(Maven)
May 17, 2022
Apache Ambari Open Redirect
Moderate
CVE-2015-5210
was published
for
org.apache.ambari:ambari
(Maven)
May 17, 2022
Jenkins affected by Open Redirect Vulnerability
High
CVE-2016-3726
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Jenkins Google Login Plugin Open Redirect vulnerability
Moderate
CVE-2018-1000174
was published
for
org.jenkins-ci.plugins:google-login
(Maven)
May 14, 2022
Cloud Foundry UAA open redirect
Moderate
CVE-2018-11041
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 14, 2022
Jenkins affected by Open Redirect Vulnerability
Low
CVE-2012-6073
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Keycloak Open Redirect
Moderate
CVE-2018-14658
was published
for
org.keycloak:keycloak-core
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API