GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
27 advisories
Filter by severity
Sort order SQL injection in Administrate
High
CVE-2020-5257
was published
for
administrate
(RubyGems)
Mar 13, 2020
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion
High
CVE-2025-24787
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Apache Camel camel-neo4j component is vulnerable to cypher injection
Moderate
CVE-2025-66169
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jan 14, 2026
FacturaScripts has SQL Injection in API ORDER BY Clause
High
CVE-2026-25513
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
FacturaScripts has SQL Injection in Autocomplete Actions
High
CVE-2026-25514
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
New API has an SQL LIKE Wildcard Injection DoS via Token Search
High
CVE-2026-25591
was published
for
github.com/QuantumNous/new-api
(Go)
Feb 23, 2026
Feathers has a NoSQL Injection via WebSocket id Parameter in MongoDB Adapter
Critical
CVE-2026-29793
was published
for
@feathersjs/mongodb
(npm)
Mar 10, 2026
Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
High
CVE-2026-30941
was published
for
parse-server
(npm)
Mar 11, 2026
Sylius has a DQL Injection via API Order Filters
Moderate
CVE-2026-31825
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
High
CVE-2026-32247
was published
for
graphiti-core
(pip)
Mar 12, 2026
Parse Server: Account takeover via operator injection in authentication data identifier
Critical
CVE-2026-32248
was published
for
parse-server
(npm)
Mar 12, 2026
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
High
CVE-2026-22743
was published
for
org.springframework.ai:spring-ai-neo4j-store
(Maven)
Mar 27, 2026
Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters
High
CVE-2026-22744
was published
for
org.springframework.ai:spring-ai-redis-store
(Maven)
Mar 27, 2026
Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
High
CVE-2026-33980
was published
for
adx-mcp-server
(pip)
Mar 27, 2026
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
High
GHSA-jfwg-rxf3-p7r9
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosure
Moderate
CVE-2026-34973
was published
for
thorsten/phpmyfaq
(Composer)
Apr 1, 2026
Flowise: Cypher Injection in GraphCypherQAChain
High
CVE-2026-41274
was published
for
flowise
(npm)
Apr 16, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Critical
CVE-2026-41327
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Critical
CVE-2026-41328
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
ShellHub has crash-DoS via field injection in filter and sort-by parameters
Moderate
CVE-2026-44425
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
Critical
CVE-2026-27886
was published
for
@strapi/strapi
(npm)
May 14, 2026
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
Moderate
CVE-2026-48121
was published
for
@langchain/langgraph-checkpoint-mongodb
(npm)
Jun 12, 2026
Budibase has nonymous NoSQL operator injection via published-app query templates
Critical
CVE-2026-54350
was published
for
@budibase/server
(npm)
Jun 23, 2026
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
High
CVE-2026-44840
was published
for
github.com/dgraph-io/dgraph/v25
(Go)
Jun 29, 2026
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
Moderate
GHSA-5c7w-4wm3-85vw
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API