GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,102 advisories
Filter by severity
Command injection vulnerability exists in the “Logging” page of the web-based configuration...
High
Unreviewed
CVE-2025-1036
was published
Oct 28, 2025
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code...
Critical
Unreviewed
CVE-2025-60803
was published
Oct 24, 2025
A command injection vulnerability may be exploited after the admin's authentication on the web...
Critical
Unreviewed
CVE-2025-7850
was published
Oct 21, 2025
An arbitrary OS command may be executed on the product by the user who can log in to the web...
High
Unreviewed
CVE-2025-6541
was published
Oct 21, 2025
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated...
High
Unreviewed
CVE-2025-10680
was published
Oct 24, 2025
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
Critical
Unreviewed
CVE-2025-6542
was published
Oct 21, 2025
Command injection vulnerability in the Edge Computing UI for the
TRO600 series radios that allows...
High
Unreviewed
CVE-2024-41153
was published
Oct 29, 2024
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection...
Critical
Unreviewed
CVE-2025-34513
was published
Oct 16, 2025
Diagnostics command injection vulnerability
High
Unreviewed
CVE-2025-6978
was published
Oct 23, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection...
High
Unreviewed
CVE-2025-34514
was published
Oct 16, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Command Injection Vulnerability
High
CVE-2021-21315
was published
for
systeminformation
(npm)
Feb 16, 2021
SaltStack Salt Command Injection in netapi ssh client
Critical
CVE-2020-16846
was published
for
salt
(pip)
May 24, 2022
Remote code execution (RCE) in Apache Airflow
High
CVE-2020-11978
was published
for
apache-airflow
(pip)
Jul 27, 2020
Command Injection in Kylin
High
CVE-2020-1956
was published
for
org.apache.kylin:kylin-core-common
(Maven)
Jul 27, 2020
Remote Code Execution Vulnerability in NPM mongo-express
Critical
CVE-2019-10758
was published
for
mongo-express
(npm)
Dec 30, 2019
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection...
Critical
Unreviewed
CVE-2016-15048
was published
Oct 22, 2025
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01...
High
Unreviewed
CVE-2024-58274
was published
Oct 22, 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of...
Critical
Unreviewed
CVE-2014-6271
was published
May 13, 2022
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function...
High
Unreviewed
CVE-2014-7169
was published
May 13, 2022
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of...
High
Unreviewed
CVE-2014-6278
was published
May 13, 2022
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user...
High
Unreviewed
CVE-2025-1976
was published
Apr 24, 2025
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI...
High
Unreviewed
CVE-2024-40890
was published
Feb 4, 2025
ProTip!
Advisories are also available from the
GraphQL API