GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
247 advisories
Filter by severity
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
High
CVE-2025-62519
was published
for
phpmyfaq/phpmyfaq
(Composer)
Nov 17, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
Django is subject to SQL injection through its column aliases
High
CVE-2025-57833
was published
for
Django
(pip)
Sep 8, 2025
PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names
High
CVE-2022-31197
was published
for
org.postgresql:postgresql
(Maven)
Aug 6, 2022
activerecord vulnerable to SQL Injection
High
CVE-2011-2930
was published
for
activerecord
(RubyGems)
Oct 24, 2017
TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
High
CVE-2025-60542
was published
for
typeorm
(npm)
Oct 29, 2025
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality
High
CVE-2025-62617
was published
for
admidio/admidio
(Composer)
Oct 22, 2025
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
High
CVE-2024-12911
was published
for
llama-index
(pip)
Mar 20, 2025
Amazon Redshift Python Connector vulnerable to SQL Injection
High
CVE-2024-12745
was published
for
redshift_connector
(pip)
Dec 26, 2024
Amazon Redshift JDBC Driver vulnerable to SQL Injection
High
CVE-2024-12744
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Dec 26, 2024
Querydsl vulnerable to HQL injection through orderBy
High
CVE-2024-49203
was published
for
com.querydsl:querydsl-apt
(Maven)
Nov 27, 2024
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
High
CVE-2022-42121
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
simple-admin-core SQL Injection vulnerability
High
CVE-2025-51667
was published
for
github.com/suyuan32/simple-admin-core
(Go)
Aug 27, 2025
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
High
CVE-2025-55156
was published
for
pyload-ng
(pip)
Aug 12, 2025
Bacula-web SQL Injection Vulnerability
High
CVE-2025-45346
was published
for
bacula-web/bacula-web
(Composer)
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names.
High
CVE-2025-54379
was published
for
github.com/lf-edge/ekuiper
(Go)
Jul 24, 2025
z-push/z-push-dev SQL Injection Vulnerability
High
CVE-2025-8264
was published
for
z-push/z-push-dev
(Composer)
Jul 29, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
Withdrawn Advisory: Daylight Studio FUEL-CMS SQLi Vulnerability
High
CVE-2020-24950
was published
for
codeigniter/framework
(Composer)
Aug 11, 2023
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API