GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,612 advisories
Filter by severity
A command injection vulnerability has been reported to affect several QNAP operating system...
High
Unreviewed
CVE-2025-30264
was published
Aug 29, 2025
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote...
High
Unreviewed
CVE-2025-29887
was published
Aug 29, 2025
A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an...
Moderate
Unreviewed
CVE-2025-9603
was published
Aug 29, 2025
An Improper Input Validation in UISP Application could allow a Command Injection by a malicious...
Low
Unreviewed
CVE-2025-48979
was published
Aug 29, 2025
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file ...
Moderate
Unreviewed
CVE-2025-9582
was published
Aug 28, 2025
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the...
Moderate
Unreviewed
CVE-2025-9581
was published
Aug 28, 2025
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9580
was published
Aug 28, 2025
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2025-9579
was published
Aug 28, 2025
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-9575
was published
Aug 28, 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the...
Critical
Unreviewed
CVE-2025-50428
was published
Aug 27, 2025
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9528
was published
Aug 27, 2025
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface...
High
Unreviewed
CVE-2025-50989
was published
Aug 27, 2025
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2025-50722
was published
Aug 26, 2025
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is...
Moderate
Unreviewed
CVE-2025-9424
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29523
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29522
was published
Aug 26, 2025
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet...
Moderate
Unreviewed
CVE-2025-44179
was published
Aug 26, 2025
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C...
Moderate
Unreviewed
CVE-2025-29519
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29516
was published
Aug 25, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29517
was published
Aug 25, 2025
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9387
was published
Aug 24, 2025
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute...
Critical
Unreviewed
CVE-2025-57105
was published
Aug 22, 2025
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was...
Moderate
Unreviewed
CVE-2025-55637
was published
Aug 22, 2025
Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command (...
High
Unreviewed
CVE-2025-41451
was published
Aug 22, 2025
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an...
Moderate
Unreviewed
CVE-2025-51818
was published
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API