GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
107 advisories
Filter by severity
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
High
CVE-2026-22743
was published
for
org.springframework.ai:spring-ai-neo4j-store
(Maven)
Mar 27, 2026
org.postgresql:postgresql vulnerable to SQL Injection via line comment generation
Critical
CVE-2024-1597
was published
for
org.postgresql:postgresql
(Maven)
Feb 21, 2024
Duplicate Advisory: SQL injection in pgjdbc
Critical
GHSA-xfg6-62px-cxc2
was published
for
org.postgresql:postgresql
(Maven)
Feb 19, 2024
•
withdrawn
SQL Injection in Spring AI MariaDBFilterExpressionConverter
High
CVE-2026-22730
was published
for
org.springframework.ai:spring-ai-mariadb-store
(Maven)
Mar 18, 2026
Apache Camel camel-neo4j component is vulnerable to cypher injection
Moderate
CVE-2025-66169
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jan 14, 2026
XWiki allows SQL injection in query endpoint of REST API with Oracle
Critical
CVE-2024-56158
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 12, 2025
XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService
Critical
CVE-2025-65091
was published
for
org.xwiki.contrib:macro-fullcalendar-pom
(Maven)
Jan 9, 2026
Hive Metastore Server is vulnerable to SQL Injection
High
CVE-2025-62728
was published
for
org.apache.hive:hive-common
(Maven)
Nov 26, 2025
Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
Moderate
CVE-2025-62228
was published
for
org.apache.flink:flink-cdc-pipeline-connectors
(Maven)
Oct 9, 2025
PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names
High
CVE-2022-31197
was published
for
org.postgresql:postgresql
(Maven)
Aug 6, 2022
MCMS vulnerable SQL injection via the content_title parameter
Critical
CVE-2025-56316
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 17, 2025
Amazon Redshift JDBC Driver vulnerable to SQL Injection
High
CVE-2024-12744
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Dec 26, 2024
Querydsl vulnerable to HQL injection through orderBy
High
CVE-2024-49203
was published
for
com.querydsl:querydsl-apt
(Maven)
Nov 27, 2024
XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
Critical
CVE-2025-52472
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Oct 6, 2025
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
Critical
CVE-2022-42122
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module
Critical
CVE-2022-42120
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
High
CVE-2022-42121
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
JeecgBoot SQL Injection Vulnerability
Moderate
CVE-2025-51825
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Aug 22, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
Critical
CVE-2025-32429
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jul 24, 2025
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL Injection
Moderate
CVE-2022-45210
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin
Moderate
CVE-2022-45208
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
Critical
CVE-2024-32888
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API