GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,071 advisories
Filter by severity
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu...
Critical
Unreviewed
CVE-2021-44247
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24144
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24148
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24150
was published
Feb 8, 2022
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45733
was published
Feb 5, 2022
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2021-45742
was published
Feb 5, 2022
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45738
was published
Feb 5, 2022
A command injection remote code execution vulnerability was discovered on Western Digital My...
Critical
Unreviewed
CVE-2022-22992
was published
Jan 29, 2022
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to...
Critical
Unreviewed
CVE-2021-46560
was published
Jan 27, 2022
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check.
Critical
Unreviewed
CVE-2022-23935
was published
Jan 26, 2022
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Critical
Unreviewed
CVE-2021-44735
was published
Jan 21, 2022
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone...
Critical
Unreviewed
CVE-2021-33963
was published
Jan 16, 2022
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController:...
Critical
Unreviewed
CVE-2021-45807
was published
Jan 14, 2022
Command Injection in node-windows
Critical
CVE-2021-45459
was published
for
node-windows
(npm)
Jan 5, 2022
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command...
Critical
Unreviewed
CVE-2021-43711
was published
Jan 5, 2022
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated...
Critical
Unreviewed
CVE-2021-45513
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45613
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45612
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45618
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45619
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45617
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45614
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45616
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45622
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45620
was published
Dec 27, 2021
ProTip!
Advisories are also available from the
GraphQL API