GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
102 advisories
Filter by severity
MCMS vulnerable SQL injection via the content_title parameter
Critical
CVE-2025-56316
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 17, 2025
Amazon Redshift JDBC Driver vulnerable to SQL Injection
High
CVE-2024-12744
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Dec 26, 2024
Querydsl vulnerable to HQL injection through orderBy
High
CVE-2024-49203
was published
for
com.querydsl:querydsl-apt
(Maven)
Nov 27, 2024
Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
Moderate
CVE-2025-62228
was published
for
org.apache.flink:flink-cdc-pipeline-connectors
(Maven)
Oct 9, 2025
XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
Critical
CVE-2025-52472
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Oct 6, 2025
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
Critical
CVE-2022-42122
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module
Critical
CVE-2022-42120
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
High
CVE-2022-42121
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
JeecgBoot SQL Injection Vulnerability
Moderate
CVE-2025-51825
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Aug 22, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
Critical
CVE-2025-32429
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jul 24, 2025
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL Injection
Moderate
CVE-2022-45210
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin
Moderate
CVE-2022-45208
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
Critical
CVE-2024-32888
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
May 15, 2024
XWiki allows SQL injection in query endpoint of REST API with Oracle
Critical
CVE-2024-56158
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 12, 2025
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
High
CVE-2021-29053
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
Critical
CVE-2025-32969
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 23, 2025
OpenMetadata SQL Injection
High
CVE-2024-55238
was published
for
org.open-metadata:openmetadata-service
(Maven)
Apr 17, 2025
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
High
CVE-2025-32968
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 23, 2025
Apache Jetspeed vulnerable to SQL Injection
High
CVE-2016-0710
was published
for
org.apache.portals.jetspeed-2:jetspeed
(Maven)
May 17, 2022
Vipshop Saturn Console Vulnerable to SQL Injection via ClusterKey Component
High
CVE-2025-29085
was published
for
com.vip.saturn:saturn-console
(Maven)
Apr 2, 2025
SQL injection in JeecgBoot
High
CVE-2024-57606
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Feb 8, 2025
Apache Cocoon SQL Injection vulnerability
Critical
CVE-2022-45135
was published
for
org.apache.cocoon:cocoon
(Maven)
Nov 30, 2023
ProTip!
Advisories are also available from the
GraphQL API