GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,990 advisories
Filter by severity
Improper Neutralization of Special Elements used in a Command in Apache Cassandra
High
CVE-2015-0225
was published
for
org.apache.cassandra:apache-cassandra
(Maven)
May 14, 2022
Command injection in czproject/git-php
High
CVE-2022-25866
was published
for
czproject/git-php
(Composer)
Apr 26, 2022
Multiple command injections and stack-based buffer overflows vulnerabilities in the...
Critical
Unreviewed
CVE-2021-26727
was published
Oct 24, 2022
Command injection and multiple stack-based buffer overflows vulnerabilities in the...
Critical
Unreviewed
CVE-2021-26729
was published
Oct 24, 2022
OS Command Injection in git-pull-or-clone
Critical
CVE-2022-24437
was published
for
git-pull-or-clone
(npm)
May 3, 2022
An exploitable command injection vulnerability exists in the web management interface used by the...
High
Unreviewed
CVE-2017-2833
was published
May 13, 2022
An exploitable command injection vulnerability exists in the web management interface used by the...
High
Unreviewed
CVE-2017-2832
was published
May 13, 2022
Command injection in npm-dependency-versions
Critical
CVE-2022-29080
was published
for
npm-dependency-versions
(npm)
Apr 13, 2022
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function...
Critical
Unreviewed
CVE-2021-26728
was published
Oct 24, 2022
A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a...
High
Unreviewed
CVE-2021-45441
was published
Jan 11, 2022
IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a...
High
Unreviewed
CVE-2021-38991
was published
Jan 12, 2022
A Remote Command Execution (RCE) vulnerability exists in HNAP1/control...
Critical
Unreviewed
CVE-2021-46314
was published
Feb 18, 2022
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and...
High
Unreviewed
CVE-2021-45806
was published
Jan 14, 2022
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create...
High
Unreviewed
CVE-2021-43286
was published
Apr 15, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb...
High
Unreviewed
CVE-2021-20160
was published
Dec 31, 2021
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2022-37070
was published
Aug 26, 2022
An authenticated user may be able to misuse parameters to inject arbitrary operating system...
High
Unreviewed
CVE-2022-0999
was published
Apr 12, 2022
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45986
was published
Feb 9, 2022
A improper neutralization of special elements used in a command ('command injection') in Fortinet...
High
Unreviewed
CVE-2021-41016
was published
Feb 8, 2022
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary...
High
Unreviewed
CVE-2021-45979
was published
Jan 5, 2022
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update...
High
Unreviewed
CVE-2021-20173
was published
Dec 31, 2021
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45987
was published
Feb 9, 2022
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects...
High
Unreviewed
CVE-2021-45602
was published
Dec 27, 2021
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary...
High
Unreviewed
CVE-2021-45978
was published
Jan 5, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log...
High
Unreviewed
CVE-2021-20159
was published
Dec 31, 2021
ProTip!
Advisories are also available from the
GraphQL API