GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,458
Erlang
33
GitHub Actions
22
Go
2,156
Maven
5,000+
npm
3,818
NuGet
693
pip
3,497
Pub
12
RubyGems
903
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,450 advisories
Filter by severity
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the...
High
Unreviewed
CVE-2024-12010
was published
Mar 11, 2025
A post-authentication command injection vulnerability in the "DNSServer” parameter of the...
High
Unreviewed
CVE-2024-11253
was published
Mar 11, 2025
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601...
High
Unreviewed
CVE-2024-12009
was published
Mar 11, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2024-53692
was published
Mar 7, 2025
A command injection vulnerability has been reported to affect QHora. If exploited, the...
High
Unreviewed
CVE-2024-50390
was published
Mar 7, 2025
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted...
Critical
Unreviewed
CVE-2025-1316
was published
Mar 5, 2025
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS...
High
Unreviewed
CVE-2024-39351
was published
Mar 4, 2025
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS...
High
Unreviewed
CVE-2023-47802
was published
Mar 4, 2025
t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via...
Moderate
Unreviewed
CVE-2025-26320
was published
Mar 4, 2025
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco...
Moderate
Unreviewed
CVE-2025-20161
was published
Feb 26, 2025
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE)...
Critical
Unreviewed
CVE-2025-27364
was published
Feb 24, 2025
A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU...
Moderate
Unreviewed
CVE-2025-1616
was published
Feb 24, 2025
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210...
Moderate
Unreviewed
CVE-2025-1546
was published
Feb 21, 2025
An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an...
Critical
Unreviewed
CVE-2025-1265
was published
Feb 20, 2025
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
High
Unreviewed
CVE-2025-26856
was published
Feb 20, 2025
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type...
High
Unreviewed
CVE-2025-25895
was published
Feb 19, 2025
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg...
High
Unreviewed
CVE-2025-25894
was published
Feb 19, 2025
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP,...
High
Unreviewed
CVE-2025-25893
was published
Feb 19, 2025
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
Critical
Unreviewed
CVE-2021-46686
was published
Feb 18, 2025
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0...
High
Unreviewed
CVE-2024-55904
was published
Feb 14, 2025
mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote...
Critical
Unreviewed
CVE-2025-25067
was published
Feb 14, 2025
A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an...
High
Unreviewed
CVE-2025-0110
was published
Feb 12, 2025
A flaw was found in the Emacs text editor. Improper handling of custom "man" URI schemes allows...
High
Unreviewed
CVE-2025-1244
was published
Feb 12, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2024-40584
was published
Feb 11, 2025
A improper neutralization of special elements used in an os command ('os command injection') in...
Moderate
Unreviewed
CVE-2024-50569
was published
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API