GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
876 advisories
Filter by severity
Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web...
High
Unreviewed
CVE-2024-24301
was published
Feb 15, 2024
When running in appliance mode, an authenticated remote command injection vulnerability exists in...
High
Unreviewed
CVE-2024-22093
was published
Feb 14, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-1354
was published
Feb 13, 2024
Azure DevOps Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20667
was published
Feb 13, 2024
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It...
High
Unreviewed
CVE-2023-40263
was published
Feb 9, 2024
An OS command injection vulnerability has been reported to affect Photo Station. If exploited,...
High
Unreviewed
CVE-2023-47562
was published
Feb 2, 2024
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method...
High
Unreviewed
CVE-2024-22107
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22900
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22903
was published
Feb 2, 2024
TRENDnet TEW-824DRU version 1.04b01 is vulnerable to Command Injection via the system.ntp.server...
High
Unreviewed
CVE-2024-22545
was published
Jan 26, 2024
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to...
High
Unreviewed
CVE-2023-51833
was published
Jan 26, 2024
HPE OneView may allow command injection with local privilege escalation.
High
Unreviewed
CVE-2023-50274
was published
Jan 23, 2024
Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection...
High
Unreviewed
CVE-2023-24135
was published
Jan 22, 2024
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters...
High
Unreviewed
CVE-2023-4797
was published
Jan 16, 2024
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and...
High
Unreviewed
CVE-2023-6634
was published
Jan 11, 2024
Azure Storage Mover Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20676
was published
Jan 9, 2024
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the...
High
Unreviewed
CVE-2023-47560
was published
Jan 5, 2024
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6,...
High
Unreviewed
CVE-2023-50445
was published
Dec 28, 2023
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute...
High
Unreviewed
CVE-2023-49226
was published
Dec 25, 2023
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user...
High
Unreviewed
CVE-2023-39509
was published
Dec 22, 2023
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical....
High
Unreviewed
CVE-2023-6848
was published
Dec 16, 2023
There is a command injection vulnerability in some ZTE mobile internet products. Due to...
High
Unreviewed
CVE-2023-25643
was published
Dec 14, 2023
An improper neutralization of special elements used in a command ('Command Injection')...
High
Unreviewed
CVE-2023-48791
was published
Dec 13, 2023
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to...
High
Unreviewed
CVE-2023-6071
was published
Nov 30, 2023
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to...
High
Unreviewed
CVE-2023-49213
was published
Nov 24, 2023
ProTip!
Advisories are also available from the
GraphQL API