GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
36 advisories
Filter by severity
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-4256
was published
Jul 9, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-13696
was published
Jul 7, 2026
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building...
Low
Unreviewed
CVE-2026-57288
was published
Jun 24, 2026
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated...
Moderate
Unreviewed
CVE-2026-44063
was published
May 21, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
Critical
Unreviewed
CVE-2026-41919
was published
May 19, 2026
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform...
Moderate
Unreviewed
CVE-2026-33609
was published
Apr 22, 2026
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can...
High
Unreviewed
CVE-2026-40459
was published
Apr 17, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29138
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29131
was published
Apr 2, 2026
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP...
Low
Unreviewed
CVE-2026-27860
was published
Mar 27, 2026
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP...
High
Unreviewed
CVE-2026-25560
was published
Feb 8, 2026
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated...
High
Unreviewed
CVE-2026-1498
was published
Jan 30, 2026
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated...
Moderate
Unreviewed
CVE-2025-35431
was published
Sep 17, 2025
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2025-48208
was published
Sep 9, 2025
Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to...
Low
Unreviewed
CVE-2025-27686
was published
Apr 7, 2025
The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an...
Moderate
Unreviewed
CVE-2025-27631
was published
Mar 25, 2025
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of...
Critical
Unreviewed
CVE-2024-54852
was published
Jan 30, 2025
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of...
Critical
Unreviewed
CVE-2024-56841
was published
Jan 14, 2025
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
Critical
Unreviewed
CVE-2024-33868
was published
May 14, 2024
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could...
High
Unreviewed
CVE-2024-22319
was published
Feb 2, 2024
NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection....
Moderate
Unreviewed
CVE-2023-31025
was published
Jan 12, 2024
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter...
High
Unreviewed
CVE-2023-29050
was published
Jan 8, 2024
A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2...
Moderate
Unreviewed
CVE-2023-6905
was published
Dec 18, 2023
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP...
High
Unreviewed
CVE-2023-3447
was published
Jun 29, 2023
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
High
Unreviewed
CVE-2022-4254
was published
Feb 1, 2023
ProTip!
Advisories are also available from the
GraphQL API