GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
18,075 advisories
Filter by severity
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
High
Unreviewed
CVE-2026-32564
was published
Aug 27, 2026
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
High
Unreviewed
CVE-2026-32550
was published
Aug 27, 2026
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond...
Critical
Unreviewed
CVE-2026-75330
was published
Aug 27, 2026
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select...
Critical
Unreviewed
CVE-2026-75336
was published
Aug 27, 2026
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The...
Critical
Unreviewed
CVE-2026-68000
was published
Aug 26, 2026
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution....
Critical
Unreviewed
CVE-2026-75334
was published
Aug 26, 2026
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Moderate
Unreviewed
CVE-2026-49809
was published
Aug 26, 2026
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges...
High
Unreviewed
CVE-2020-15878
was published
Aug 26, 2026
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges...
High
Unreviewed
CVE-2020-15876
was published
Aug 26, 2026
Efence developed by Thinking Software Technology has a SQL Injection vulnerability....
High
Unreviewed
CVE-2026-80236
was published
Aug 26, 2026
With legitimate user credentials in hand, attackers can construct malicious SQL statements to...
Moderate
Unreviewed
CVE-2026-9668
was published
Aug 26, 2026
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via ...
High
Unreviewed
CVE-2026-18884
was published
Aug 26, 2026
The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database...
Moderate
Unreviewed
CVE-2026-19094
was published
Aug 26, 2026
A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit...
Moderate
Unreviewed
CVE-2026-38467
was published
Aug 26, 2026
A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall...
Moderate
Unreviewed
CVE-2026-38468
was published
Aug 26, 2026
The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads...
Moderate
Unreviewed
CVE-2026-78468
was published
Aug 25, 2026
Webkul QloApps does not validate request parameters before a database query. A remote,...
High
Unreviewed
CVE-2026-75498
was published
Aug 25, 2026
Webkul QloApps does not validate request parameters before a database query. A remote,...
High
Unreviewed
CVE-2026-75497
was published
Aug 25, 2026
The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL...
Moderate
Unreviewed
CVE-2026-77824
was published
Aug 25, 2026
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via...
High
Unreviewed
CVE-2026-19949
was published
Aug 25, 2026
The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 ...
High
Unreviewed
CVE-2026-78576
was published
Aug 25, 2026
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to,...
Critical
Unreviewed
CVE-2026-78568
was published
Aug 25, 2026
The extension fails to properly sanitize user input before using it in a database query. As a...
High
Unreviewed
CVE-2026-77137
was published
Aug 25, 2026
The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up...
Moderate
Unreviewed
CVE-2026-78470
was published
Aug 25, 2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-15023
was published
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API