GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
17,853 advisories
Filter by severity
An authenticated attacker with low privileges can access an endpoint in the controller’s web...
Moderate
Unreviewed
CVE-2025-41771
was published
Aug 12, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2026-66659
was published
Aug 12, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used...
Critical
Unreviewed
CVE-2026-48381
was published
Aug 11, 2026
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad...
High
Unreviewed
CVE-2016-20097
was published
Aug 11, 2026
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the...
High
Unreviewed
CVE-2022-50997
was published
Aug 11, 2026
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the...
Moderate
Unreviewed
CVE-2026-72775
was published
Aug 11, 2026
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake...
Moderate
Unreviewed
CVE-2026-72750
was published
Aug 11, 2026
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01...
Moderate
Unreviewed
CVE-2026-72610
was published
Aug 11, 2026
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01...
Moderate
Unreviewed
CVE-2026-72608
was published
Aug 11, 2026
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows...
High
Unreviewed
CVE-2026-72609
was published
Aug 11, 2026
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01...
High
Unreviewed
CVE-2026-72607
was published
Aug 11, 2026
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute...
Critical
Unreviewed
CVE-2026-72599
was published
Aug 11, 2026
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows...
High
Unreviewed
CVE-2026-72562
was published
Aug 11, 2026
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read...
High
Unreviewed
CVE-2026-72558
was published
Aug 11, 2026
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated...
Critical
Unreviewed
CVE-2026-72550
was published
Aug 11, 2026
Travel Agency Management System developed by Win Men Intermational has a SQL Injection...
Critical
Unreviewed
CVE-2026-19425
was published
Aug 11, 2026
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could...
Moderate
Unreviewed
CVE-2026-66770
was published
Aug 11, 2026
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0...
Critical
Unreviewed
CVE-2025-13294
was published
Aug 10, 2026
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the...
Critical
Unreviewed
CVE-2026-63106
was published
Aug 10, 2026
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote...
Critical
Unreviewed
CVE-2026-72565
was published
Aug 10, 2026
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are...
Unknown
Unreviewed
CVE-2026-32227
was published
Aug 10, 2026
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter...
Critical
Unreviewed
CVE-2026-19053
was published
Aug 10, 2026
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user...
Moderate
Unreviewed
CVE-2026-18666
was published
Aug 10, 2026
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before...
High
Unreviewed
CVE-2026-19049
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API