GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
18,074 advisories
Filter by severity
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low...
High
Unreviewed
CVE-2026-19754
was published
Sep 2, 2026
AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the...
High
Unreviewed
CVE-2026-84208
was published
Sep 2, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
High
Unreviewed
CVE-2026-18630
was published
Sep 1, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
Critical
Unreviewed
CVE-2026-18210
was published
Sep 1, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
Critical
Unreviewed
CVE-2026-18765
was published
Sep 1, 2026
The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations &...
Moderate
Unreviewed
CVE-2026-77189
was published
Sep 1, 2026
The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via ...
Moderate
Unreviewed
CVE-2026-18752
was published
Sep 1, 2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection...
Moderate
Unreviewed
CVE-2026-17589
was published
Sep 1, 2026
The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of...
Moderate
Unreviewed
CVE-2026-77823
was published
Sep 1, 2026
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic...
Moderate
Unreviewed
CVE-2026-76006
was published
Sep 1, 2026
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
High
Unreviewed
CVE-2026-81287
was published
Aug 31, 2026
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
Critical
Unreviewed
CVE-2026-81293
was published
Aug 31, 2026
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
Critical
Unreviewed
CVE-2026-81756
was published
Aug 31, 2026
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Critical
Unreviewed
CVE-2026-81763
was published
Aug 31, 2026
WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the ...
High
Unreviewed
CVE-2026-75132
was published
Aug 31, 2026
Improper neutralization of special elements used in an SQL command ('SQL injection')...
High
Unreviewed
CVE-2026-5956
was published
Aug 31, 2026
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list...
High
Unreviewed
CVE-2026-82655
was published
Aug 30, 2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape...
Moderate
Unreviewed
CVE-2026-80488
was published
Aug 29, 2026
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from...
High
Unreviewed
CVE-2026-16061
was published
Aug 29, 2026
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send...
Critical
Unreviewed
CVE-2026-3627
was published
Aug 29, 2026
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
Moderate
CVE-2026-55855
was published
for
mariadb
(npm)
Aug 28, 2026
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are...
High
Unreviewed
CVE-2026-77586
was published
Aug 28, 2026
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is...
Moderate
Unreviewed
CVE-2026-77184
was published
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
High
CVE-2026-55208
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API