GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,162 advisories
Filter by severity
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-0616
was published
Oct 3, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype...
High
Unreviewed
CVE-2025-52041
was published
Oct 1, 2025
In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype...
High
Unreviewed
CVE-2025-52042
was published
Oct 1, 2025
In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext...
High
Unreviewed
CVE-2025-52039
was published
Oct 1, 2025
The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the...
High
Unreviewed
CVE-2025-8877
was published
Sep 30, 2025
Improper neutralization of input provided by an authorized user in article positioning...
High
Unreviewed
CVE-2025-8121
was published
Sep 30, 2025
Improper neutralization of input provided by an authorized user in article positioning...
High
Unreviewed
CVE-2025-8122
was published
Sep 30, 2025
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an...
High
Unreviewed
CVE-2025-6724
was published
Sep 29, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60107
was published
Sep 26, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60118
was published
Sep 26, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60109
was published
Sep 26, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60110
was published
Sep 26, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-60108
was published
Sep 26, 2025
This vulnerability allows attackers to directly query the underlying database, potentially...
High
Unreviewed
CVE-2025-59816
was published
Sep 25, 2025
Ericsson
Indoor Connect 8855 contains a SQL injection vulnerability
which if exploited can lead...
High
Unreviewed
CVE-2025-27261
was published
Sep 25, 2025
SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows...
High
Unreviewed
CVE-2025-40698
was published
Sep 25, 2025
The vulnerability allows any application installed on the device to read SMS/MMS data and...
High
Unreviewed
CVE-2025-10184
was published
Sep 23, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-59570
was published
Sep 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58686
was published
Sep 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-53468
was published
Sep 22, 2025
SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows...
High
Unreviewed
CVE-2025-40677
was published
Sep 18, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-13174
was published
Sep 16, 2025
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute...
High
Unreviewed
CVE-2025-44034
was published
Sep 16, 2025
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is...
High
Unreviewed
CVE-2025-52044
was published
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API