Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

18,086 advisories

Loading
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers Critical
CVE-2026-76904 was published for org.geotools.jdbc:gt-jdbc-postgis (Maven) Aug 21, 2026
qquang Credited to qquang, mrlihd, PhilipPhil, Quikko, jodygarnett, h1ei1, and 4ra1n mrlihd mrlihd
PhilipPhil PhilipPhil Quikko Quikko jodygarnett jodygarnett h1ei1 h1ei1 4ra1n 4ra1n
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database High
CVE-2026-54245 was published for github.com/fleetdm/fleet (Go) Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Critical Unreviewed
CVE-2026-63039 was published Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Critical Unreviewed
CVE-2026-63038 was published Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Critical Unreviewed
CVE-2026-63037 was published Aug 20, 2026
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. High Unreviewed
CVE-2026-73998 was published Aug 20, 2026
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. High Unreviewed
CVE-2026-74013 was published Aug 20, 2026
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. Critical Unreviewed
CVE-2026-66680 was published Aug 20, 2026
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. Critical Unreviewed
CVE-2026-68566 was published Aug 20, 2026
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. High Unreviewed
CVE-2026-66594 was published Aug 20, 2026
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. Critical Unreviewed
CVE-2026-66609 was published Aug 20, 2026
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. Critical Unreviewed
CVE-2026-66593 was published Aug 20, 2026
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. Critical Unreviewed
CVE-2026-66649 was published Aug 20, 2026
Unauthenticated SQL Injection in Capella <= 2.5.5 versions. Critical Unreviewed
CVE-2025-15688 was published Aug 20, 2026
ProTip! Advisories are also available from the GraphQL API