GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
18,086 advisories
Filter by severity
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
Critical
CVE-2026-76904
was published
for
org.geotools.jdbc:gt-jdbc-postgis
(Maven)
Aug 21, 2026
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5...
Critical
Unreviewed
CVE-2026-76613
was published
Aug 21, 2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter...
Moderate
Unreviewed
CVE-2026-16959
was published
Aug 21, 2026
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a...
Moderate
Unreviewed
CVE-2026-14601
was published
Aug 21, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL...
Critical
Unreviewed
CVE-2026-68782
was published
Aug 21, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL...
Critical
Unreviewed
CVE-2026-68789
was published
Aug 21, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
High
CVE-2026-54245
was published
for
github.com/fleetdm/fleet
(Go)
Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2026-63039
was published
Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2026-63038
was published
Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2026-63037
was published
Aug 20, 2026
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows...
High
Unreviewed
CVE-2026-76635
was published
Aug 20, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2026-74011
was published
Aug 20, 2026
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
High
Unreviewed
CVE-2026-73998
was published
Aug 20, 2026
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
High
Unreviewed
CVE-2026-74013
was published
Aug 20, 2026
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Critical
Unreviewed
CVE-2026-66680
was published
Aug 20, 2026
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Critical
Unreviewed
CVE-2026-68566
was published
Aug 20, 2026
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in...
High
Unreviewed
CVE-2026-77071
was published
Aug 20, 2026
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
High
Unreviewed
CVE-2026-66594
was published
Aug 20, 2026
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Critical
Unreviewed
CVE-2026-66609
was published
Aug 20, 2026
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Critical
Unreviewed
CVE-2026-66593
was published
Aug 20, 2026
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Critical
Unreviewed
CVE-2026-66649
was published
Aug 20, 2026
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Critical
Unreviewed
CVE-2025-15688
was published
Aug 20, 2026
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Critical
Unreviewed
CVE-2026-66592
was published
Aug 20, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role...
Moderate
Unreviewed
CVE-2026-76364
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API