GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,930
Maven
5,000+
npm
4,587
NuGet
786
pip
4,294
Pub
12
RubyGems
981
Rust
1,114
Swift
49
Unreviewed advisories
All unreviewed
5,000+
611 advisories
Filter by severity
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
Critical
CVE-2026-25544
was published
for
@payloadcms/drizzle
(npm)
Feb 5, 2026
OpenSTAManager has an SQL Injection in the Stampe Module
High
CVE-2025-69215
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
High
CVE-2025-69213
was published
for
devcode-it/openstamanager
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in Autocomplete Actions
High
CVE-2026-25514
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in API ORDER BY Clause
High
CVE-2026-25513
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
High
CVE-2025-69662
was published
for
geopandas
(pip)
Jan 30, 2026
EGroupware has SQL Injection in Nextmatch Filter Processing
High
CVE-2026-22243
was published
for
egroupware/egroupware
(Composer)
Jan 28, 2026
LibreNMS contains an authenticated SQL Injection vulnerability
High
CVE-2020-36947
was published
for
librenms/librenms
(Composer)
Jan 27, 2026
Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM
Moderate
GHSA-38cw-85xc-xr9x
was published
for
@veramo/data-store
(npm)
Jan 16, 2026
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
High
GHSA-5qw5-wf2q-f538
was published
for
activerecord-jdbc-adapter
(RubyGems)
Jan 16, 2026
Aimeos contains a SQL injection vulnerability in the json api 'sort' parameter
High
CVE-2021-47763
was published
for
aimeos/aimeos-laravel
(Composer)
Jan 15, 2026
Pimcore Has an Incomplete Patch for CVE-2023-30848
High
CVE-2026-23492
was published
for
pimcore/pimcore
(Composer)
Jan 14, 2026
Apache Camel camel-neo4j component is vulnerable to cypher injection
Moderate
CVE-2025-66169
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jan 14, 2026
WeKnora vulnerable to SQL Injection
High
CVE-2026-22687
was published
for
github.com/Tencent/WeKnora
(Go)
Jan 9, 2026
XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService
Critical
CVE-2025-65091
was published
for
org.xwiki.contrib:macro-fullcalendar-pom
(Maven)
Jan 9, 2026
Ghost has SQL Injection in Members Activity Feed
Moderate
CVE-2026-22596
was published
for
ghost
(npm)
Jan 8, 2026
CoreShop Vulnerable to SQL Injection via Admin Reports
Moderate
CVE-2026-22242
was published
for
coreshop/core-shop
(Composer)
Jan 7, 2026
Parsl Monitoring Visualization Vulnerable to SQL Injection
Moderate
CVE-2026-21892
was published
for
parsl
(pip)
Jan 6, 2026
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
High
CVE-2025-67644
was published
for
langgraph-checkpoint-sqlite
(pip)
Dec 10, 2025
assyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Hive Metastore Server is vulnerable to SQL Injection
High
CVE-2025-62728
was published
for
org.apache.hive:hive-common
(Maven)
Nov 26, 2025
ProTip!
Advisories are also available from the
GraphQL API