GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,080 advisories
Filter by severity
SQL injection in prestashop/prestashop
High
CVE-2021-43789
was published
for
prestashop/prestashop
(Composer)
Dec 7, 2021
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token...
High
Unreviewed
CVE-2021-40313
was published
Dec 7, 2021
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function...
High
Unreviewed
CVE-2021-25784
was published
Dec 4, 2021
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function...
High
Unreviewed
CVE-2021-25783
was published
Dec 4, 2021
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before...
High
Unreviewed
CVE-2020-35012
was published
Dec 3, 2021
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A...
High
Unreviewed
CVE-2021-36328
was published
Dec 1, 2021
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before...
High
Unreviewed
CVE-2021-24755
was published
Nov 30, 2021
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the...
High
Unreviewed
CVE-2021-24748
was published
Nov 30, 2021
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields...
High
Unreviewed
CVE-2021-24889
was published
Nov 30, 2021
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and...
High
Unreviewed
CVE-2021-24860
was published
Nov 30, 2021
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal...
High
Unreviewed
CVE-2021-36807
was published
Nov 27, 2021
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL...
High
Unreviewed
CVE-2021-36299
was published
Nov 24, 2021
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An...
High
Unreviewed
CVE-2021-36300
was published
Nov 24, 2021
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager...
High
Unreviewed
CVE-2021-24847
was published
Nov 17, 2021
SQL injection in Apache DolphinScheduler
High
CVE-2021-27644
was published
for
org.apache.dolphinscheduler:dolphinscheduler-server
(Maven)
Nov 3, 2021
Content object state fetch functions open to SQL injection
High
GHSA-jpwx-ffjq-wr4w
was published
for
ezsystems/ezpublish-legacy
(Composer)
Sep 7, 2021
Unauthenticated SQL Injection in Cachet
High
CVE-2021-39165
was published
for
cachethq/cachet
(Composer)
Aug 30, 2021
SQL injection in pimcore/pimcore
High
CVE-2021-23405
was published
for
pimcore/pimcore
(Composer)
Jul 13, 2021
SQL Injection in Cloud Native Computing Foundation Harbor
High
CVE-2019-19029
was published
for
github.com/goharbor/harbor
(Go)
May 18, 2021
SQL Injection in pimcore
High
CVE-2020-7759
was published
for
pimcore/pimcore
(Composer)
May 6, 2021
SQL Injection in librenms
High
CVE-2020-35700
was published
for
librenms/librenms
(Composer)
May 6, 2021
SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database
High
GHSA-4mg9-vhxq-vm7j
was published
for
illuminate/database
(Composer)
Apr 29, 2021
ProTip!
Advisories are also available from the
GraphQL API