GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,989 advisories
Filter by severity
OS Command Injection in git-pull-or-clone
Critical
CVE-2022-24437
was published
for
git-pull-or-clone
(npm)
May 3, 2022
D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr...
Critical
Unreviewed
CVE-2022-28571
was published
May 3, 2022
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in ...
High
Unreviewed
CVE-2022-28572
was published
May 3, 2022
D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-28573
was published
May 3, 2022
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for...
High
Unreviewed
CVE-2010-0136
was published
May 2, 2022
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1...
High
Unreviewed
CVE-2007-3010
was published
May 1, 2022
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows...
High
Unreviewed
CVE-2005-2793
was published
May 1, 2022
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary...
High
Unreviewed
CVE-2005-2773
was published
May 1, 2022
Sed Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An...
High
Unreviewed
CVE-2022-1509
was published
Apr 29, 2022
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web...
High
Unreviewed
CVE-2021-34592
was published
Apr 28, 2022
The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the...
High
Unreviewed
CVE-2022-26111
was published
Apr 26, 2022
Command injection in czproject/git-php
High
CVE-2022-25866
was published
for
czproject/git-php
(Composer)
Apr 26, 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject...
High
Unreviewed
CVE-2022-27924
was published
Apr 22, 2022
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show...
Critical
Unreviewed
CVE-2010-5330
was published
Apr 21, 2022
An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi...
Critical
Unreviewed
CVE-2009-5156
was published
Apr 21, 2022
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell...
High
Unreviewed
CVE-2009-5157
was published
Apr 21, 2022
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create...
High
Unreviewed
CVE-2021-43286
was published
Apr 15, 2022
In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into...
Critical
Unreviewed
CVE-2015-20107
was published
Apr 14, 2022
Command injection in npm-dependency-versions
Critical
CVE-2022-29080
was published
for
npm-dependency-versions
(npm)
Apr 13, 2022
An authenticated user may be able to misuse parameters to inject arbitrary operating system...
High
Unreviewed
CVE-2022-0999
was published
Apr 12, 2022
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain...
Critical
Unreviewed
CVE-2022-27268
was published
Apr 11, 2022
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain...
Critical
Unreviewed
CVE-2022-27276
was published
Apr 11, 2022
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain...
Critical
Unreviewed
CVE-2022-27269
was published
Apr 11, 2022
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain...
Critical
Unreviewed
CVE-2022-27271
was published
Apr 11, 2022
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain...
Critical
Unreviewed
CVE-2022-27274
was published
Apr 11, 2022
ProTip!
Advisories are also available from the
GraphQL API