GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,048 advisories
Filter by severity
The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize...
Moderate
Unreviewed
CVE-2025-60641
was published
Oct 16, 2025
Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax...
Moderate
Unreviewed
CVE-2025-56700
was published
Oct 16, 2025
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open...
Moderate
Unreviewed
CVE-2025-56699
was published
Oct 16, 2025
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
Moderate
Unreviewed
CVE-2025-61540
was published
Oct 16, 2025
The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter...
Moderate
Unreviewed
CVE-2025-10660
was published
Oct 15, 2025
The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and...
Moderate
Unreviewed
CVE-2025-10682
was published
Oct 15, 2025
The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber...
Moderate
Unreviewed
CVE-2025-10730
was published
Oct 15, 2025
The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id'...
Moderate
Unreviewed
CVE-2025-11365
was published
Oct 15, 2025
The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last'...
Moderate
Unreviewed
CVE-2025-10310
was published
Oct 15, 2025
The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode...
Moderate
Unreviewed
CVE-2025-10575
was published
Oct 15, 2025
The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order'...
Moderate
Unreviewed
CVE-2025-10045
was published
Oct 15, 2025
A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2025-11736
was published
Oct 14, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft...
Moderate
Unreviewed
CVE-2025-55320
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62390
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62392
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62385
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62386
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62387
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62383
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62384
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62388
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62391
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-11623
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62389
was published
Oct 14, 2025
A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-11668
was published
Oct 13, 2025
ProTip!
Advisories are also available from the
GraphQL API