GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,992 advisories
Filter by severity
A command injection vulnerability has been reported to affect QHora. If exploited, the...
Moderate
Unreviewed
CVE-2024-53700
was published
Mar 7, 2025
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote...
High
Unreviewed
CVE-2025-29887
was published
Aug 29, 2025
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker...
High
Unreviewed
CVE-2025-20334
was published
Sep 24, 2025
An administrator is able to execute commands as root via the alerts management dialog
High
Unreviewed
CVE-2021-4406
was published
Jul 10, 2023
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
High
Unreviewed
CVE-2025-22481
was published
Jun 6, 2025
A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown...
Moderate
Unreviewed
CVE-2025-10774
was published
Sep 22, 2025
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the...
Moderate
Unreviewed
CVE-2025-57296
was published
Sep 22, 2025
In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code...
High
Unreviewed
CVE-2025-43953
was published
Sep 22, 2025
A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the...
Low
Unreviewed
CVE-2025-10767
was published
Sep 22, 2025
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability...
Moderate
Unreviewed
CVE-2025-10775
was published
Sep 22, 2025
A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10629
was published
Sep 18, 2025
A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code...
Moderate
Unreviewed
CVE-2025-10628
was published
Sep 18, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
High
Unreviewed
CVE-2025-30264
was published
Aug 29, 2025
The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in...
High
Unreviewed
CVE-2014-0773
was published
May 17, 2022
FitNesse allows execution of arbitrary OS commands
Critical
CVE-2024-28125
was published
for
org.fitnesse:fitnesse
(Maven)
Mar 18, 2024
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe...
High
Unreviewed
CVE-2025-57293
was published
Sep 18, 2025
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the...
Moderate
Unreviewed
CVE-2025-55911
was published
Sep 18, 2025
The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins...
High
Unreviewed
CVE-2023-49565
was published
Sep 18, 2025
Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie...
Moderate
Unreviewed
CVE-2025-50891
was published
Aug 19, 2025
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
High
Unreviewed
CVE-2024-6333
was published
Oct 17, 2024
In JetBrains Junie before 252.284.66,
251.284.66,
243.284.66,
252.284.61,
251.284.61,
243.284.61,...
High
Unreviewed
CVE-2025-59458
was published
Sep 17, 2025
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability...
High
Unreviewed
CVE-2025-56706
was published
Sep 16, 2025
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command...
High
Unreviewed
CVE-2024-12992
was published
Mar 17, 2025
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command...
High
Unreviewed
CVE-2024-12971
was published
Mar 17, 2025
ProTip!
Advisories are also available from the
GraphQL API