GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
38 advisories
Filter by severity
n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the...
Moderate
Unreviewed
CVE-2026-85167
was published
Sep 3, 2026
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to...
Moderate
Unreviewed
CVE-2026-63138
was published
Sep 1, 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST ...
Moderate
Unreviewed
CVE-2026-79483
was published
Aug 31, 2026
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer...
Moderate
Unreviewed
CVE-2026-81527
was published
Aug 27, 2026
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that...
Moderate
Unreviewed
CVE-2026-81528
was published
Aug 27, 2026
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller...
Moderate
Unreviewed
CVE-2026-59319
was published
Aug 27, 2026
The extension allows a request-provided additionalFilters parameter to register a named siteHash...
Moderate
Unreviewed
CVE-2026-56094
was published
Aug 25, 2026
The extension passes the user-supplied search query parameter to Apache Solr without restricting...
Moderate
Unreviewed
CVE-2026-56096
was published
Aug 25, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run...
Moderate
Unreviewed
CVE-2026-76363
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could...
Moderate
Unreviewed
CVE-2026-76349
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user...
Moderate
Unreviewed
CVE-2026-76329
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway...
Moderate
Unreviewed
CVE-2026-76327
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user...
Moderate
Unreviewed
CVE-2026-76320
was published
Aug 20, 2026
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
Moderate
GHSA-pqh8-p93p-2rx7
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit...
Moderate
Unreviewed
CVE-2026-8649
was published
Jul 8, 2026
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
Moderate
GHSA-5c7w-4wm3-85vw
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
Moderate
CVE-2026-54019
was published
for
open-webui
(pip)
Jun 17, 2026
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
Moderate
CVE-2026-48121
was published
for
@langchain/langgraph-checkpoint-mongodb
(npm)
Jun 12, 2026
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
Moderate
CVE-2026-41697
was published
for
org.springframework.data:spring-data-relational
(Maven)
Jun 10, 2026
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
Moderate
CVE-2026-41696
was published
for
org.springframework.data:spring-data-mongodb
(Maven)
Jun 10, 2026
ShellHub has crash-DoS via field injection in filter and sort-by parameters
Moderate
CVE-2026-44425
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows...
Moderate
Unreviewed
CVE-2026-33566
was published
Apr 27, 2026
phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosure
Moderate
CVE-2026-34973
was published
for
thorsten/phpmyfaq
(Composer)
Apr 1, 2026
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically...
Moderate
Unreviewed
CVE-2026-3023
was published
Mar 16, 2026
Sylius has a DQL Injection via API Order Filters
Moderate
CVE-2026-31825
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API