GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,640
Maven
5,000+
npm
4,265
NuGet
760
pip
4,061
Pub
12
RubyGems
956
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15,540 advisories
Filter by severity
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via...
High
Unreviewed
CVE-2022-28006
was published
Apr 22, 2022
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM ...
High
Unreviewed
CVE-2022-20786
was published
Apr 22, 2022
SQL injection vulnerability in Jifty::DBI before 0.68.
Critical
Unreviewed
CVE-2011-1933
was published
Apr 22, 2022
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when...
Critical
Unreviewed
CVE-2011-1939
was published
Apr 22, 2022
Typo3 SQL injection due to faulty prepared statements
Critical
CVE-2011-3583
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Drupal SQL Injection vulnerability
Critical
CVE-2011-2715
was published
for
drupal/core
(Composer)
Apr 22, 2022
Jara 1.6 has a SQL injection vulnerability.
Critical
Unreviewed
CVE-2011-4094
was published
Apr 22, 2022
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management...
Critical
Unreviewed
CVE-2022-27341
was published
Apr 23, 2022
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest...
Critical
Unreviewed
CVE-2022-27342
was published
Apr 23, 2022
SQL Injection found in Pimcore
High
CVE-2022-1429
was published
for
pimcore/pimcore
(Composer)
Apr 23, 2022
SQL injection vulnerability in the Yet another TYPO3 search engine (YATSE) extension before 0.3.2...
High
Unreviewed
CVE-2010-1004
was published
Apr 23, 2022
SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows...
High
Unreviewed
CVE-2010-1006
was published
Apr 23, 2022
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
Critical
Unreviewed
CVE-2012-6719
was published
Apr 23, 2022
Contao core SQL Injection Vulnerability
High
CVE-2012-4383
was published
for
contao/core
(Composer)
Apr 23, 2022
SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress...
High
Unreviewed
CVE-2022-29419
was published
Apr 26, 2022
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id...
Critical
Unreviewed
CVE-2022-0782
was published
Apr 26, 2022
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not...
Critical
Unreviewed
CVE-2022-0657
was published
Apr 26, 2022
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids...
Critical
Unreviewed
CVE-2022-0693
was published
Apr 26, 2022
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the...
Critical
Unreviewed
CVE-2022-0769
was published
Apr 26, 2022
The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not escape the artID...
High
Unreviewed
CVE-2021-24957
was published
Apr 26, 2022
A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select...
High
Unreviewed
CVE-2022-29603
was published
Apr 26, 2022
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post...
Critical
Unreviewed
CVE-2022-28524
was published
Apr 27, 2022
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts...
Critical
Unreviewed
CVE-2022-27985
was published
Apr 27, 2022
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter...
Critical
Unreviewed
CVE-2022-27984
was published
Apr 27, 2022
ProTip!
Advisories are also available from the
GraphQL API