GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
3,817 advisories
Filter by severity
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and...
Critical
Unreviewed
CVE-2021-24943
was published
Dec 7, 2021
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the...
Critical
Unreviewed
CVE-2021-24866
was published
Dec 7, 2021
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated...
Critical
Unreviewed
CVE-2021-43035
was published
Dec 7, 2021
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below...
Critical
Unreviewed
CVE-2021-29114
was published
Dec 8, 2021
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3...
Critical
Unreviewed
CVE-2021-41063
was published
Dec 9, 2021
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in...
Critical
Unreviewed
CVE-2021-41695
was published
Dec 10, 2021
wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Critical
Unreviewed
CVE-2021-3817
was published
Dec 10, 2021
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System...
Critical
Unreviewed
CVE-2021-44966
was published
Dec 14, 2021
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id...
Critical
Unreviewed
CVE-2021-24951
was published
Dec 14, 2021
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the...
Critical
Unreviewed
CVE-2021-24946
was published
Dec 14, 2021
The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots...
Critical
Unreviewed
CVE-2021-24863
was published
Dec 14, 2021
If configured to use an Oracle database and if a query is created using the flexible search java...
Critical
Unreviewed
CVE-2021-42064
was published
Dec 15, 2021
There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id...
Critical
Unreviewed
CVE-2021-45014
was published
Dec 15, 2021
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication...
Critical
Unreviewed
CVE-2021-44655
was published
Dec 16, 2021
Online Magazine Management System 1.0 contains a SQL injection authentication bypass...
Critical
Unreviewed
CVE-2021-44653
was published
Dec 16, 2021
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE...
Critical
Unreviewed
CVE-2021-42313
was published
Dec 16, 2021
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE...
Critical
Unreviewed
CVE-2021-42311
was published
Dec 16, 2021
A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask...
Critical
Unreviewed
CVE-2021-42945
was published
Dec 16, 2021
ThinkPHP5 SQL Injection vulnerability
Critical
CVE-2021-44350
was published
for
topthink/framework
(Composer)
Dec 17, 2021
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice...
Critical
Unreviewed
CVE-2021-40850
was published
Dec 18, 2021
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL...
Critical
Unreviewed
CVE-2021-45255
was published
Dec 22, 2021
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For...
Critical
Unreviewed
CVE-2021-45252
was published
Dec 22, 2021
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be...
Critical
Unreviewed
CVE-2021-45253
was published
Dec 22, 2021
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12,...
Critical
Unreviewed
CVE-2021-24849
was published
Dec 22, 2021
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R...
Critical
Unreviewed
CVE-2021-21916
was published
Dec 23, 2021
ProTip!
Advisories are also available from the
GraphQL API