GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
23 advisories
Filter by severity
EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC...
High
Unreviewed
CVE-2016-9870
was published
May 17, 2022
LDAP Injection in is-user-valid
High
CVE-2021-23335
was published
for
is-user-valid
(npm)
Apr 13, 2021
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle...
High
Unreviewed
CVE-2017-4927
was published
May 17, 2022
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
High
Unreviewed
CVE-2022-4254
was published
Feb 1, 2023
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter...
High
Unreviewed
CVE-2023-29050
was published
Jan 8, 2024
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could...
High
Unreviewed
CVE-2024-22319
was published
Feb 2, 2024
Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
High
CVE-2021-41232
was published
for
github.com/stevenweathers/thunderdome-planning-poker
(Go)
Nov 8, 2021
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0,...
High
Unreviewed
CVE-2019-11277
was published
May 24, 2022
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP...
High
Unreviewed
CVE-2023-3447
was published
Jun 29, 2023
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2025-48208
was published
Sep 9, 2025
pgAdmin is affected by an LDAP injection vulnerability
High
CVE-2025-12764
was published
for
pgadmin4
(pip)
Nov 13, 2025
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated...
High
Unreviewed
CVE-2026-1498
was published
Jan 30, 2026
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP...
High
Unreviewed
CVE-2026-25560
was published
Feb 8, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username
High
CVE-2026-40193
was published
for
github.com/foxcpp/maddy
(Go)
Apr 13, 2026
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can...
High
Unreviewed
CVE-2026-40459
was published
Apr 17, 2026
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
High
CVE-2026-44304
was published
for
lemur
(pip)
May 6, 2026
ZITADEL has LDAP Filter Injection in Login Flow
High
CVE-2026-44671
was published
for
github.com/zitadel/zitadel
(Go)
May 8, 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
High
CVE-2026-49268
was published
for
org.apache.shiro:shiro-core
(Maven)
Jun 17, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection
High
CVE-2026-46619
was published
for
org.openidentityplatform.openam:openam-auth-msisdn
(Maven)
Jun 26, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-13696
was published
Jul 7, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-4256
was published
Jul 9, 2026
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-47303
was published
for
Microsoft.AspNetCore.Authentication.Negotiate
(NuGet)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API