GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
49 advisories
Filter by severity
Potential Command Injection in codem-transcode
High
CVE-2013-7377
was published
for
codem-transcode
(npm)
Nov 28, 2017
Command Injection in cocos-utils
High
GHSA-rffp-mc78-wjf7
was published
for
cocos-utils
(npm)
Sep 2, 2020
Unauthenticated Remote Command Injection in ep_imageconvert
High
CVE-2013-3364
was published
for
ep_imageconvert
(npm)
Aug 31, 2020
Command Injection in expressfs
High
GHSA-mxmj-84q8-34r7
was published
for
expressfs
(npm)
Sep 3, 2020
Command Injection in soletta-dev-app
High
GHSA-8mgg-5x65-m4m4
was published
for
soletta-dev-app
(npm)
Sep 11, 2020
Command Injection in entitlements
High
GHSA-g8vp-6hv4-m67c
was published
for
entitlements
(npm)
Sep 11, 2020
git-archive vulnerable to Command Injection via exports function
High
CVE-2020-28422
was published
for
git-archive
(npm)
Jul 26, 2022
OS Command Injection in git-promise
High
CVE-2022-24376
was published
for
git-promise
(npm)
Jun 11, 2022
Command injection in node-dns-sync
High
CVE-2020-11079
was published
for
dns-sync
(npm)
May 28, 2020
Command injection in kill-process-on-port
High
CVE-2020-28426
was published
for
kill-process-on-port
(npm)
Mar 19, 2021
Command Injection Vulnerability in systeminformation
High
CVE-2021-21388
was published
for
systeminformation
(npm)
Apr 6, 2021
ProTip!
Advisories are also available from the
GraphQL API