GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,002 advisories
Filter by severity
In Boa, there is a possible command injection due to improper input validation. This could lead...
Critical
Unreviewed
CVE-2022-32665
was published
Jan 3, 2023
The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which...
Critical
Unreviewed
CVE-2023-0039
was published
Jan 3, 2023
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some...
Critical
Unreviewed
CVE-2017-20156
was published
Dec 31, 2022
Apache Kylin vulnerable to Command injection by Useless configuration
High
CVE-2022-43396
was published
for
org.apache.kylin:kylin
(Maven)
Dec 30, 2022
Apache Kylin vulnerable to Command injection by Diagnosis Controller
Critical
CVE-2022-44621
was published
for
org.apache.kylin:kylin-server-base
(Maven)
Dec 30, 2022
Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s...
High
Unreviewed
CVE-2022-45796
was published
Dec 27, 2022
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-45717
was published
Dec 23, 2022
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-46642
was published
Dec 23, 2022
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-46641
was published
Dec 23, 2022
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been...
High
Unreviewed
CVE-2020-15685
was published
Dec 22, 2022
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped...
High
Unreviewed
CVE-2022-22744
was published
Dec 22, 2022
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac...
Critical
Unreviewed
CVE-2022-46538
was published
Dec 20, 2022
Apache Airflow Hive Provider vulnerable to Command Injection
Critical
CVE-2022-46421
was published
for
apache-airflow-providers-apache-hive
(pip)
Dec 20, 2022
The default console presented to users over telnet (when enabled) is restricted to a subset of...
High
Unreviewed
CVE-2022-47210
was published
Dec 16, 2022
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-46631
was published
Dec 16, 2022
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-46634
was published
Dec 16, 2022
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI...
Critical
Unreviewed
CVE-2022-31702
was published
Dec 14, 2022
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-44832
was published
Dec 14, 2022
cycle-import-check vulnerable to Command Injection
Critical
CVE-2022-24377
was published
for
cycle-import-check
(npm)
Dec 14, 2022
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-45005
was published
Dec 13, 2022
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and...
Critical
Unreviewed
CVE-2022-46404
was published
Dec 13, 2022
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
High
Unreviewed
CVE-2022-45996
was published
Dec 12, 2022
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface....
High
Unreviewed
CVE-2022-37912
was published
Dec 12, 2022
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface....
High
Unreviewed
CVE-2022-37902
was published
Dec 12, 2022
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface....
High
Unreviewed
CVE-2022-37901
was published
Dec 12, 2022
ProTip!
Advisories are also available from the
GraphQL API