GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,267 advisories
Filter by severity
FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified...
Critical
Unreviewed
CVE-2018-0694
was published
May 14, 2022
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices...
Critical
Unreviewed
CVE-2018-12670
was published
May 14, 2022
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via...
Critical
Unreviewed
CVE-2018-16167
was published
May 14, 2022
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote...
Critical
Unreviewed
CVE-2018-19646
was published
May 14, 2022
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command...
Critical
Unreviewed
CVE-2019-7297
was published
May 14, 2022
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to...
Critical
Unreviewed
CVE-2016-1142
was published
May 14, 2022
GIG Technology NV JumpScale Portal 7 version before commit...
Critical
Unreviewed
CVE-2018-1000666
was published
May 14, 2022
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively....
Critical
Unreviewed
CVE-2019-9118
was published
May 14, 2022
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively....
Critical
Unreviewed
CVE-2019-9117
was published
May 14, 2022
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively....
Critical
Unreviewed
CVE-2019-9120
was published
May 14, 2022
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively....
Critical
Unreviewed
CVE-2019-9119
was published
May 14, 2022
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001...
Critical
Unreviewed
CVE-2018-11229
was published
May 14, 2022
A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote...
Critical
Unreviewed
CVE-2018-6444
was published
May 14, 2022
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers...
Critical
Unreviewed
CVE-2018-6911
was published
May 14, 2022
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13...
Critical
Unreviewed
CVE-2018-7890
was published
May 13, 2022
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command...
Critical
Unreviewed
CVE-2018-7440
was published
May 13, 2022
A server auth command injection authentication bypass vulnerability in Trend Micro Smart...
Critical
Unreviewed
CVE-2018-6231
was published
May 13, 2022
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the...
Critical
Unreviewed
CVE-2018-5347
was published
May 13, 2022
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form...
Critical
Unreviewed
CVE-2018-20218
was published
May 13, 2022
Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi...
Critical
Unreviewed
CVE-2018-19168
was published
May 13, 2022
In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote...
Critical
Unreviewed
CVE-2018-19290
was published
May 13, 2022
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03...
Critical
Unreviewed
CVE-2018-18728
was published
May 13, 2022
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell...
Critical
Unreviewed
CVE-2018-18555
was published
May 13, 2022
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell...
Critical
Unreviewed
CVE-2018-18322
was published
May 13, 2022
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0...
Critical
Unreviewed
CVE-2018-17565
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API