GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,200 advisories
Filter by severity
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60110
was published
Sep 26, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60107
was published
Sep 26, 2025
This vulnerability allows attackers to directly query the underlying database, potentially...
High
Unreviewed
CVE-2025-59816
was published
Sep 25, 2025
Ericsson
Indoor Connect 8855 contains a SQL injection vulnerability
which if exploited can lead...
High
Unreviewed
CVE-2025-27261
was published
Sep 25, 2025
SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows...
High
Unreviewed
CVE-2025-40698
was published
Sep 25, 2025
The vulnerability allows any application installed on the device to read SMS/MMS data and...
High
Unreviewed
CVE-2025-10184
was published
Sep 23, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-59570
was published
Sep 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58686
was published
Sep 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-53468
was published
Sep 22, 2025
SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows...
High
Unreviewed
CVE-2025-40677
was published
Sep 18, 2025
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is...
High
Unreviewed
CVE-2025-52044
was published
Sep 16, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-13174
was published
Sep 16, 2025
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute...
High
Unreviewed
CVE-2025-44034
was published
Sep 16, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-12913
was published
Sep 16, 2025
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting...
High
Unreviewed
CVE-2025-27240
was published
Sep 12, 2025
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s...
High
Unreviewed
CVE-2025-9807
was published
Sep 12, 2025
The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id'...
High
Unreviewed
CVE-2025-9073
was published
Sep 11, 2025
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This...
High
Unreviewed
CVE-2025-56407
was published
Sep 10, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58993
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-59008
was published
Sep 9, 2025
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and...
High
Unreviewed
CVE-2025-55849
was published
Sep 8, 2025
Django is subject to SQL injection through its column aliases
High
CVE-2025-57833
was published
for
Django
(pip)
Sep 8, 2025
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app...
High
Unreviewed
CVE-2025-56630
was published
Sep 8, 2025
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15...
High
Unreviewed
CVE-2025-58439
was published
Sep 6, 2025
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request.
High
Unreviewed
CVE-2025-58780
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API