GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,189 advisories
Filter by severity
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in...
High
Unreviewed
CVE-2025-34242
was published
Nov 6, 2025
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in...
High
Unreviewed
CVE-2025-34240
was published
Nov 6, 2025
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote...
High
Unreviewed
CVE-2025-13769
was published
Nov 28, 2025
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote...
High
Unreviewed
CVE-2025-13770
was published
Nov 28, 2025
Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user...
High
Unreviewed
CVE-2025-11461
was published
Nov 26, 2025
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low...
High
Unreviewed
CVE-2013-10044
was published
Aug 1, 2025
Improper neutralization of input provided by an authorized user in article positioning...
High
Unreviewed
CVE-2025-8121
was published
Sep 30, 2025
Improper neutralization of input provided by an authorized user in article positioning...
High
Unreviewed
CVE-2025-8122
was published
Sep 30, 2025
PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM...
High
Unreviewed
CVE-2025-66260
was published
Nov 26, 2025
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP...
High
Unreviewed
CVE-2022-50591
was published
Nov 6, 2025
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
High
Unreviewed
CVE-2025-56401
was published
Nov 24, 2025
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP...
High
Unreviewed
CVE-2022-50594
was published
Nov 6, 2025
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is...
High
Unreviewed
CVE-2025-7402
was published
Nov 24, 2025
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search'...
High
Unreviewed
CVE-2025-13138
was published
Nov 21, 2025
Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index...
High
Unreviewed
CVE-2025-63719
was published
Nov 19, 2025
OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter
High
CVE-2025-65103
was published
for
devcode-it/openstamanager
(Composer)
Nov 19, 2025
SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability...
High
Unreviewed
CVE-2025-41348
was published
Nov 18, 2025
The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear'...
High
Unreviewed
CVE-2025-12646
was published
Nov 19, 2025
An improper neutralization of special elements used in an SQL Command ("SQL Injection")...
High
Unreviewed
CVE-2025-58692
was published
Nov 18, 2025
The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL...
High
Unreviewed
CVE-2025-12411
was published
Nov 18, 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a...
High
Unreviewed
CVE-2019-9053
was published
May 14, 2022
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
High
CVE-2025-62519
was published
for
phpmyfaq/phpmyfaq
(Composer)
Nov 17, 2025
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-12482
was published
Nov 16, 2025
The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for...
High
Unreviewed
CVE-2025-11188
was published
Oct 10, 2025
ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source...
High
Unreviewed
CVE-2022-4984
was published
Nov 13, 2025
ProTip!
Advisories are also available from the
GraphQL API