GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8644
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8631
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8628
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8630
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8629
was published
Aug 6, 2025
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev...
Critical
Unreviewed
CVE-2013-10069
was published
Aug 5, 2025
Narcissus is vulnerable to remote code execution via improper input handling in its image...
Critical
Unreviewed
CVE-2012-10033
was published
Aug 5, 2025
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command...
High
Unreviewed
CVE-2012-10029
was published
Aug 5, 2025
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative...
High
Unreviewed
CVE-2012-10028
was published
Aug 5, 2025
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection....
High
Unreviewed
CVE-2025-43978
was published
Aug 5, 2025
An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated...
High
Unreviewed
CVE-2025-43979
was published
Aug 5, 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre...
Critical
Unreviewed
CVE-2025-54948
was published
Aug 5, 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre...
Critical
Unreviewed
CVE-2025-54987
was published
Aug 5, 2025
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi...
Critical
Unreviewed
CVE-2025-34147
was published
Aug 4, 2025
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2025-51390
was published
Aug 4, 2025
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain...
High
Unreviewed
CVE-2025-44960
was published
Aug 4, 2025
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP...
Critical
Unreviewed
CVE-2025-44961
was published
Aug 4, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its...
High
Unreviewed
CVE-2025-36606
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
High
Unreviewed
CVE-2025-30099
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30097
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30098
was published
Aug 4, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its...
High
Unreviewed
CVE-2025-36607
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30096
was published
Aug 4, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-36604
was published
Aug 4, 2025
Claude Code echo command allowed bypass of user approval prompt for command execution
High
CVE-2025-54795
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
ProTip!
Advisories are also available from the
GraphQL API