GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15,541 advisories
Filter by severity
ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source...
High
Unreviewed
CVE-2022-4984
was published
Nov 13, 2025
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-12620
was published
Nov 13, 2025
A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0...
Critical
Unreviewed
CVE-2025-56385
was published
Nov 12, 2025
A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to...
Critical
Unreviewed
CVE-2025-64280
was published
Nov 12, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-64293
was published
Nov 12, 2025
The Specific Content For Mobile – Customize the mobile version without redirections plugin for...
Moderate
Unreviewed
CVE-2025-11454
was published
Nov 12, 2025
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection...
High
Unreviewed
CVE-2025-13046
was published
Nov 12, 2025
Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection...
High
Unreviewed
CVE-2025-13047
was published
Nov 12, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL...
High
Unreviewed
CVE-2025-59499
was published
Nov 11, 2025
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated...
Critical
Unreviewed
CVE-2025-8324
was published
Nov 11, 2025
SAP Starter Solution allows an authenticated attacker to execute crafted database queries,...
Moderate
Unreviewed
CVE-2025-42889
was published
Nov 11, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy...
High
Unreviewed
CVE-2025-63497
was published
Nov 10, 2025
A SQL injection vulnerability was found in Looker Studio.
A Looker Studio user with report view...
High
Unreviewed
CVE-2025-12397
was published
Nov 10, 2025
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration...
High
Unreviewed
CVE-2025-12409
was published
Nov 10, 2025
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing...
High
Unreviewed
CVE-2025-12865
was published
Nov 10, 2025
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing...
High
Unreviewed
CVE-2025-12864
was published
Nov 10, 2025
The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the ...
Moderate
Unreviewed
CVE-2025-11980
was published
Nov 8, 2025
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-11972
was published
Nov 8, 2025
The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE[...
High
Unreviewed
CVE-2025-11452
was published
Nov 8, 2025
A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System)...
Moderate
Unreviewed
CVE-2025-63718
was published
Nov 7, 2025
Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit...
Critical
Unreviewed
CVE-2025-63689
was published
Nov 7, 2025
An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit...
Critical
Unreviewed
CVE-2025-52425
was published
Nov 7, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 -...
High
Unreviewed
CVE-2025-10968
was published
Nov 7, 2025
SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create,...
Critical
Unreviewed
CVE-2025-10870
was published
Nov 7, 2025
ProTip!
Advisories are also available from the
GraphQL API