GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
46 advisories
Filter by severity
Bouncy Castle has an LDAP injection
Moderate
CVE-2026-0636
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Apr 17, 2026
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can...
High
Unreviewed
CVE-2026-40459
was published
Apr 17, 2026
mitmproxy has an LDAP Injection
Moderate
CVE-2026-40606
was published
for
mitmproxy
(pip)
Apr 14, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username
High
CVE-2026-40193
was published
for
github.com/foxcpp/maddy
(Go)
Apr 13, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29131
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29138
was published
Apr 2, 2026
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP...
Low
Unreviewed
CVE-2026-27860
was published
Mar 27, 2026
n8n Vulnerable to LDAP Filter Injection in LDAP Node
Moderate
CVE-2026-33751
was published
for
n8n
(npm)
Mar 26, 2026
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP...
High
Unreviewed
CVE-2026-25560
was published
Feb 8, 2026
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated...
High
Unreviewed
CVE-2026-1498
was published
Jan 30, 2026
Moonraker affected by LDAP search filter injection
Low
CVE-2026-24130
was published
for
moonraker
(pip)
Jan 22, 2026
pgAdmin is affected by an LDAP injection vulnerability
High
CVE-2025-12764
was published
for
pgadmin4
(pip)
Nov 13, 2025
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated...
Moderate
Unreviewed
CVE-2025-35431
was published
Sep 17, 2025
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2025-48208
was published
Sep 9, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection
Moderate
CVE-2025-4573
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to...
Low
Unreviewed
CVE-2025-27686
was published
Apr 7, 2025
The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an...
Moderate
Unreviewed
CVE-2025-27631
was published
Mar 25, 2025
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of...
Critical
Unreviewed
CVE-2024-54852
was published
Jan 30, 2025
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of...
Critical
Unreviewed
CVE-2024-56841
was published
Jan 14, 2025
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
Critical
Unreviewed
CVE-2024-33868
was published
May 14, 2024
Apache Zeppelin: LDAP search filter query Injection Vulnerability
Moderate
CVE-2024-31867
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could...
High
Unreviewed
CVE-2024-22319
was published
Feb 2, 2024
NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection....
Moderate
Unreviewed
CVE-2023-31025
was published
Jan 12, 2024
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter...
High
Unreviewed
CVE-2023-29050
was published
Jan 8, 2024
ProTip!
Advisories are also available from the
GraphQL API