GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
79 advisories
Filter by severity
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio...
High
Unreviewed
CVE-2026-62906
was published
Sep 4, 2026
n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the...
Moderate
Unreviewed
CVE-2026-85167
was published
Sep 3, 2026
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to...
Moderate
Unreviewed
CVE-2026-63138
was published
Sep 1, 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST ...
Moderate
Unreviewed
CVE-2026-79483
was published
Aug 31, 2026
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer...
Moderate
Unreviewed
CVE-2026-81527
was published
Aug 27, 2026
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that...
Moderate
Unreviewed
CVE-2026-81528
was published
Aug 27, 2026
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller...
Moderate
Unreviewed
CVE-2026-59319
was published
Aug 27, 2026
The extension allows a request-provided additionalFilters parameter to register a named siteHash...
Moderate
Unreviewed
CVE-2026-56094
was published
Aug 25, 2026
The extension passes the user-supplied search query parameter to Apache Solr without restricting...
Moderate
Unreviewed
CVE-2026-56096
was published
Aug 25, 2026
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
High
CVE-2026-55253
was published
for
langgraph-checkpoint-mongodb
(pip)
Aug 20, 2026
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB...
High
Unreviewed
CVE-2026-77070
was published
Aug 20, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run...
Moderate
Unreviewed
CVE-2026-76363
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could...
Moderate
Unreviewed
CVE-2026-76349
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
High
Unreviewed
CVE-2026-76331
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user...
Moderate
Unreviewed
CVE-2026-76329
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway...
Moderate
Unreviewed
CVE-2026-76327
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user...
Moderate
Unreviewed
CVE-2026-76320
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user...
High
Unreviewed
CVE-2026-76316
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an...
High
Unreviewed
CVE-2026-76254
was published
Aug 20, 2026
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource...
High
Unreviewed
CVE-2026-73617
was published
Aug 13, 2026
Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query...
High
Unreviewed
CVE-2026-73618
was published
Aug 13, 2026
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
Moderate
GHSA-pqh8-p93p-2rx7
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
High
GHSA-qw6m-8fw2-2v64
was published
for
@budibase/server
(npm)
Jul 24, 2026
AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability...
High
Unreviewed
CVE-2025-60357
was published
Jul 17, 2026
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit...
Moderate
Unreviewed
CVE-2026-8649
was published
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API