GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,969
Erlang
39
GitHub Actions
38
Go
2,622
Maven
5,000+
npm
4,255
NuGet
760
pip
4,045
Pub
12
RubyGems
953
Rust
1,050
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15,479 advisories
Filter by severity
MCMS vulnerable SQL injection via the content_title parameter
Critical
CVE-2025-56316
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 17, 2025
A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The...
Moderate
Unreviewed
CVE-2025-11909
was published
Oct 17, 2025
Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder...
Moderate
Unreviewed
CVE-2025-60514
was published
Oct 17, 2025
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-11903
was published
Oct 17, 2025
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function...
Moderate
Unreviewed
CVE-2025-11904
was published
Oct 17, 2025
A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-11902
was published
Oct 17, 2025
The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize...
Moderate
Unreviewed
CVE-2025-60641
was published
Oct 16, 2025
Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax...
Moderate
Unreviewed
CVE-2025-56700
was published
Oct 16, 2025
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open...
Moderate
Unreviewed
CVE-2025-56699
was published
Oct 16, 2025
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
Moderate
Unreviewed
CVE-2025-61540
was published
Oct 16, 2025
SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve,...
Critical
Unreviewed
CVE-2025-41019
was published
Oct 16, 2025
SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve,...
Critical
Unreviewed
CVE-2025-41018
was published
Oct 16, 2025
The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in...
High
Unreviewed
CVE-2025-11177
was published
Oct 15, 2025
The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last'...
Moderate
Unreviewed
CVE-2025-10310
was published
Oct 15, 2025
The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id'...
Moderate
Unreviewed
CVE-2025-11365
was published
Oct 15, 2025
The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter...
Moderate
Unreviewed
CVE-2025-10660
was published
Oct 15, 2025
The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode...
Moderate
Unreviewed
CVE-2025-10575
was published
Oct 15, 2025
The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber...
Moderate
Unreviewed
CVE-2025-10730
was published
Oct 15, 2025
The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and...
Moderate
Unreviewed
CVE-2025-10682
was published
Oct 15, 2025
The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all...
High
Unreviewed
CVE-2025-10743
was published
Oct 15, 2025
The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order'...
Moderate
Unreviewed
CVE-2025-10045
was published
Oct 15, 2025
The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the ...
High
Unreviewed
CVE-2025-11501
was published
Oct 15, 2025
A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2025-11736
was published
Oct 14, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft...
High
Unreviewed
CVE-2025-59213
was published
Oct 14, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft...
Moderate
Unreviewed
CVE-2025-55320
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API