GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
774 advisories
Filter by severity
Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in...
Critical
Unreviewed
CVE-2023-46370
was published
Oct 25, 2023
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
Critical
Unreviewed
CVE-2023-36953
was published
Oct 16, 2023
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
Critical
Unreviewed
CVE-2023-36954
was published
Oct 16, 2023
In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass...
Critical
Unreviewed
CVE-2023-45852
was published
Oct 14, 2023
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2023-45465
was published
Oct 13, 2023
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2023-45466
was published
Oct 13, 2023
A command execution vulnerability exists in the validate.so diag_ping_start functionality of...
Critical
Unreviewed
CVE-2023-32632
was published
Oct 11, 2023
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2023-43891
was published
Oct 3, 2023
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection...
Critical
Unreviewed
CVE-2023-43128
was published
Sep 22, 2023
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2023-43206
was published
Sep 20, 2023
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2023-43204
was published
Sep 20, 2023
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2023-43207
was published
Sep 20, 2023
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2023-43202
was published
Sep 20, 2023
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2023-39638
was published
Sep 15, 2023
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home...
Critical
Unreviewed
CVE-2023-41011
was published
Sep 14, 2023
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page...
Critical
Unreviewed
CVE-2023-3710
was published
Sep 12, 2023
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2023-39637
was published
Sep 12, 2023
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2...
Critical
Unreviewed
CVE-2023-4310
was published
Sep 5, 2023
SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command...
Critical
Unreviewed
CVE-2023-38027
was published
Aug 28, 2023
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-39834
was published
Aug 24, 2023
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to...
Critical
Unreviewed
CVE-2023-39617
was published
Aug 21, 2023
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2023-39809
was published
Aug 21, 2023
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2023-39618
was published
Aug 21, 2023
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection...
Critical
Unreviewed
CVE-2023-34215
was published
Aug 17, 2023
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and...
Critical
Unreviewed
CVE-2023-34214
was published
Aug 17, 2023
ProTip!
Advisories are also available from the
GraphQL API