GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
15,096 advisories
Filter by severity
The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions...
High
Unreviewed
CVE-2023-1016
was published
Jun 9, 2023
The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via...
Moderate
Unreviewed
CVE-2023-1615
was published
Jun 9, 2023
The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id...
High
Unreviewed
CVE-2023-2237
was published
Jun 9, 2023
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection...
Moderate
Unreviewed
CVE-2023-2484
was published
Jun 9, 2023
The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via...
High
Unreviewed
CVE-2023-2607
was published
Jun 9, 2023
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at ...
High
Unreviewed
CVE-2023-33557
was published
Jun 9, 2023
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022...
Critical
Unreviewed
CVE-2023-35036
was published
Jun 12, 2023
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID...
Critical
Unreviewed
CVE-2023-34581
was published
Jun 12, 2023
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify...
Moderate
Unreviewed
CVE-2023-32115
was published
Jun 13, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-3047
was published
Jun 13, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-35064
was published
Jun 13, 2023
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
High
Unreviewed
CVE-2023-33817
was published
Jun 13, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at...
Critical
Unreviewed
CVE-2023-34750
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at...
Critical
Unreviewed
CVE-2023-34751
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at...
Critical
Unreviewed
CVE-2023-34752
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at...
Critical
Unreviewed
CVE-2023-34753
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at...
Critical
Unreviewed
CVE-2023-34754
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter...
Critical
Unreviewed
CVE-2023-34755
was published
Jun 14, 2023
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at...
Critical
Unreviewed
CVE-2023-34756
was published
Jun 14, 2023
PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via...
Critical
Unreviewed
CVE-2023-31671
was published
Jun 14, 2023
PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax...
Critical
Unreviewed
CVE-2023-30150
was published
Jun 14, 2023
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
Moderate
Unreviewed
CVE-2023-34626
was published
Jun 15, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-2080
was published
Jun 16, 2023
Thinking Software Efence login function has insufficient validation for user input. An...
Critical
Unreviewed
CVE-2023-32754
was published
Jun 16, 2023
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
Critical
Unreviewed
CVE-2023-34548
was published
Jun 16, 2023
ProTip!
Advisories are also available from the
GraphQL API