GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
13,129 advisories
Filter by severity
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL...
Moderate
Unreviewed
CVE-2024-35148
was published
Jan 25, 2025
A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The...
Critical
Unreviewed
CVE-2024-57328
was published
Jan 24, 2025
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9,...
Critical
Unreviewed
CVE-2024-55573
was published
Jan 24, 2025
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x...
Critical
Unreviewed
CVE-2024-53923
was published
Jan 24, 2025
The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id...
High
Unreviewed
CVE-2024-4318
was published
May 16, 2024
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and...
Moderate
Unreviewed
CVE-2023-2660
was published
May 11, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24659
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24672
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24669
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24728
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24587
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24663
was published
Jan 24, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-24683
was published
Jan 24, 2025
The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category'...
Moderate
Unreviewed
CVE-2024-13594
was published
Jan 24, 2025
The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of...
Moderate
Unreviewed
CVE-2024-13680
was published
Jan 24, 2025
SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-25227
was published
Mar 15, 2024
The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-1795
was published
Mar 15, 2024
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2023-27112
was published
Jan 22, 2025
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2023-27113
was published
Jan 22, 2025
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’...
High
Unreviewed
CVE-2024-10400
was published
Jan 23, 2025
The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id'...
Moderate
Unreviewed
CVE-2024-13236
was published
Jan 23, 2025
The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the ...
High
Unreviewed
CVE-2024-13234
was published
Jan 23, 2025
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote...
Critical
Unreviewed
CVE-2016-2386
was published
May 13, 2022
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the...
High
Unreviewed
CVE-2024-57769
was published
Jan 16, 2025
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility...
Critical
Unreviewed
CVE-2024-24101
was published
Mar 13, 2024
ProTip!
Advisories are also available from the
GraphQL API