GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,189 advisories
Filter by severity
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote...
High
Unreviewed
CVE-2025-13769
was published
Nov 28, 2025
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote...
High
Unreviewed
CVE-2025-13770
was published
Nov 28, 2025
Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user...
High
Unreviewed
CVE-2025-11461
was published
Nov 26, 2025
PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM...
High
Unreviewed
CVE-2025-66260
was published
Nov 26, 2025
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
High
Unreviewed
CVE-2025-56401
was published
Nov 24, 2025
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is...
High
Unreviewed
CVE-2025-7402
was published
Nov 24, 2025
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search'...
High
Unreviewed
CVE-2025-13138
was published
Nov 21, 2025
Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index...
High
Unreviewed
CVE-2025-63719
was published
Nov 19, 2025
OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter
High
CVE-2025-65103
was published
for
devcode-it/openstamanager
(Composer)
Nov 19, 2025
The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear'...
High
Unreviewed
CVE-2025-12646
was published
Nov 19, 2025
An improper neutralization of special elements used in an SQL Command ("SQL Injection")...
High
Unreviewed
CVE-2025-58692
was published
Nov 18, 2025
SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability...
High
Unreviewed
CVE-2025-41348
was published
Nov 18, 2025
The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL...
High
Unreviewed
CVE-2025-12411
was published
Nov 18, 2025
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
High
CVE-2025-62519
was published
for
phpmyfaq/phpmyfaq
(Composer)
Nov 17, 2025
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-12482
was published
Nov 16, 2025
ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source...
High
Unreviewed
CVE-2022-4984
was published
Nov 13, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-64293
was published
Nov 12, 2025
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection...
High
Unreviewed
CVE-2025-13046
was published
Nov 12, 2025
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection...
High
Unreviewed
CVE-2025-13047
was published
Nov 12, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL...
High
Unreviewed
CVE-2025-59499
was published
Nov 11, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy...
High
Unreviewed
CVE-2025-63497
was published
Nov 10, 2025
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration...
High
Unreviewed
CVE-2025-12409
was published
Nov 10, 2025
A SQL injection vulnerability was found in Looker Studio.
A Looker Studio user with report view...
High
Unreviewed
CVE-2025-12397
was published
Nov 10, 2025
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing...
High
Unreviewed
CVE-2025-12865
was published
Nov 10, 2025
ProTip!
Advisories are also available from the
GraphQL API