GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,542 advisories
Filter by severity
Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn"...
Critical
Unreviewed
CVE-2021-43155
was published
Dec 23, 2021
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter...
Critical
Unreviewed
CVE-2021-43157
was published
Dec 23, 2021
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple...
Critical
Unreviewed
CVE-2021-43629
was published
Dec 23, 2021
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email...
Critical
Unreviewed
CVE-2021-43628
was published
Dec 23, 2021
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the...
Critical
Unreviewed
CVE-2021-43631
was published
Dec 23, 2021
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R...
Critical
Unreviewed
CVE-2021-21916
was published
Dec 23, 2021
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12,...
Critical
Unreviewed
CVE-2021-24849
was published
Dec 22, 2021
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be...
Critical
Unreviewed
CVE-2021-45253
was published
Dec 22, 2021
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For...
Critical
Unreviewed
CVE-2021-45252
was published
Dec 22, 2021
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL...
Critical
Unreviewed
CVE-2021-45255
was published
Dec 22, 2021
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice...
Critical
Unreviewed
CVE-2021-40850
was published
Dec 18, 2021
A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask...
Critical
Unreviewed
CVE-2021-42945
was published
Dec 16, 2021
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE...
Critical
Unreviewed
CVE-2021-42311
was published
Dec 16, 2021
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE...
Critical
Unreviewed
CVE-2021-42313
was published
Dec 16, 2021
Online Magazine Management System 1.0 contains a SQL injection authentication bypass...
Critical
Unreviewed
CVE-2021-44653
was published
Dec 16, 2021
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication...
Critical
Unreviewed
CVE-2021-44655
was published
Dec 16, 2021
There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id...
Critical
Unreviewed
CVE-2021-45014
was published
Dec 15, 2021
If configured to use an Oracle database and if a query is created using the flexible search java...
Critical
Unreviewed
CVE-2021-42064
was published
Dec 15, 2021
The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots...
Critical
Unreviewed
CVE-2021-24863
was published
Dec 14, 2021
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the...
Critical
Unreviewed
CVE-2021-24946
was published
Dec 14, 2021
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id...
Critical
Unreviewed
CVE-2021-24951
was published
Dec 14, 2021
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System...
Critical
Unreviewed
CVE-2021-44966
was published
Dec 14, 2021
wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Critical
Unreviewed
CVE-2021-3817
was published
Dec 10, 2021
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in...
Critical
Unreviewed
CVE-2021-41695
was published
Dec 10, 2021
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3...
Critical
Unreviewed
CVE-2021-41063
was published
Dec 9, 2021
ProTip!
Advisories are also available from the
GraphQL API