GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,239
NuGet
754
pip
4,003
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15,324 advisories
Filter by severity
The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize...
Moderate
Unreviewed
CVE-2025-60641
was published
Oct 16, 2025
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open...
Moderate
Unreviewed
CVE-2025-56699
was published
Oct 16, 2025
Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax...
Moderate
Unreviewed
CVE-2025-56700
was published
Oct 16, 2025
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
Moderate
Unreviewed
CVE-2025-61540
was published
Oct 16, 2025
SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve,...
Critical
Unreviewed
CVE-2025-41018
was published
Oct 16, 2025
SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve,...
Critical
Unreviewed
CVE-2025-41019
was published
Oct 16, 2025
The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in...
High
Unreviewed
CVE-2025-11177
was published
Oct 15, 2025
The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all...
High
Unreviewed
CVE-2025-10743
was published
Oct 15, 2025
The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber...
Moderate
Unreviewed
CVE-2025-10730
was published
Oct 15, 2025
The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id'...
Moderate
Unreviewed
CVE-2025-11365
was published
Oct 15, 2025
The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last'...
Moderate
Unreviewed
CVE-2025-10310
was published
Oct 15, 2025
The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode...
Moderate
Unreviewed
CVE-2025-10575
was published
Oct 15, 2025
The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and...
Moderate
Unreviewed
CVE-2025-10682
was published
Oct 15, 2025
The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter...
Moderate
Unreviewed
CVE-2025-10660
was published
Oct 15, 2025
The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order'...
Moderate
Unreviewed
CVE-2025-10045
was published
Oct 15, 2025
The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the ...
High
Unreviewed
CVE-2025-11501
was published
Oct 15, 2025
A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is...
Moderate
Unreviewed
CVE-2025-11736
was published
Oct 14, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft...
High
Unreviewed
CVE-2025-59213
was published
Oct 14, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft...
Moderate
Unreviewed
CVE-2025-55320
was published
Oct 14, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-10610
was published
Oct 14, 2025
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications...
High
Unreviewed
CVE-2025-40755
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62390
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62392
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-11623
was published
Oct 14, 2025
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary...
Moderate
Unreviewed
CVE-2025-62383
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API