GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
89 advisories
Filter by severity
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
Critical
CVE-2026-34934
was published
for
praisonai
(pip)
Apr 1, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
Critical
CVE-2026-32714
was published
for
scitokens
(pip)
Mar 31, 2026
MobSF has SQL Injection in its SQLite Database Viewer Utils
Moderate
CVE-2026-33545
was published
for
mobsf
(pip)
Mar 24, 2026
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
High
CVE-2026-32611
was published
for
Glances
(pip)
Mar 16, 2026
Vanna has a SQL injection in the remove_training_data function
Moderate
CVE-2026-4229
was published
for
vanna
(pip)
Mar 16, 2026
Glances has SQL Injection via Process Names in TimescaleDB Export
High
CVE-2026-30930
was published
for
Glances
(pip)
Mar 9, 2026
CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
High
CVE-2026-28438
was published
for
cocoindex
(pip)
Mar 2, 2026
Apache Superset allows privileged users to conduct error-based SQL Injection
Moderate
CVE-2026-23980
was published
for
apache-superset
(pip)
Feb 24, 2026
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Moderate
CVE-2026-23969
was published
for
apache-superset
(pip)
Feb 24, 2026
ormar is vulnerable to SQL Injection through aggregate functions min() and max()
Critical
CVE-2026-26198
was published
for
ormar
(pip)
Feb 23, 2026
geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
High
CVE-2025-69662
was published
for
geopandas
(pip)
Jan 30, 2026
Parsl Monitoring Visualization Vulnerable to SQL Injection
Moderate
CVE-2026-21892
was published
for
parsl
(pip)
Jan 6, 2026
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
High
CVE-2025-67644
was published
for
langgraph-checkpoint-sqlite
(pip)
Dec 10, 2025
asyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
Django is subject to SQL injection through its column aliases
High
CVE-2025-57833
was published
for
Django
(pip)
Sep 8, 2025
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Moderate
CVE-2025-55674
was published
for
apache-superset
(pip)
Aug 14, 2025
ProTip!
Advisories are also available from the
GraphQL API