GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,930
Maven
5,000+
npm
4,587
NuGet
786
pip
4,294
Pub
12
RubyGems
981
Rust
1,114
Swift
49
Unreviewed advisories
All unreviewed
5,000+
79 advisories
Filter by severity
geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
High
CVE-2025-69662
was published
for
geopandas
(pip)
Jan 30, 2026
Parsl Monitoring Visualization Vulnerable to SQL Injection
Moderate
CVE-2026-21892
was published
for
parsl
(pip)
Jan 6, 2026
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
High
CVE-2025-67644
was published
for
langgraph-checkpoint-sqlite
(pip)
Dec 10, 2025
assyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
Django is subject to SQL injection through its column aliases
High
CVE-2025-57833
was published
for
Django
(pip)
Sep 8, 2025
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Moderate
CVE-2025-55674
was published
for
apache-superset
(pip)
Aug 14, 2025
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
High
CVE-2025-55156
was published
for
pyload-ng
(pip)
Aug 12, 2025
llama_index vulnerable to SQL Injection
Critical
CVE-2025-1793
was published
for
llama-index
(pip)
Jun 5, 2025
Apache Superset: Improper authorization bypass on row level security via SQL Injection
High
CVE-2025-48912
was published
for
apache-superset
(pip)
May 30, 2025
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
High
CVE-2025-30473
was published
for
apache-airflow-providers-common-sql
(pip)
Apr 7, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30217
was published
for
frappe
(pip)
Mar 26, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30212
was published
for
frappe
(pip)
Mar 25, 2025
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
High
CVE-2024-12911
was published
for
llama-index
(pip)
Mar 20, 2025
llama-index-packs-finchat SQL Injection vulnerability
Critical
CVE-2024-12909
was published
for
llama-index-packs-finchat
(pip)
Mar 20, 2025
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
Critical
CVE-2024-11958
was published
for
llama-index-retrievers-duckdb-retriever
(pip)
Mar 20, 2025
DB-GPT Arbitrary File Write vulnerability
Critical
CVE-2024-10901
was published
for
dbgpt
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API