GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,992 advisories
Filter by severity
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface...
High
Unreviewed
CVE-2025-50989
was published
Aug 27, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29517
was published
Aug 25, 2025
1Panel agent certificate verification bypass leading to arbitrary command execution
High
CVE-2025-54424
was published
for
github.com/1Panel-dev/1Panel/core
(Go)
Aug 1, 2025
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet...
Moderate
Unreviewed
CVE-2025-44179
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29522
was published
Aug 26, 2025
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C...
Moderate
Unreviewed
CVE-2025-29519
was published
Aug 26, 2025
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute...
Critical
Unreviewed
CVE-2025-57105
was published
Aug 22, 2025
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2025-50722
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29523
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29516
was published
Aug 25, 2025
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was...
Moderate
Unreviewed
CVE-2025-55637
was published
Aug 22, 2025
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an...
Moderate
Unreviewed
CVE-2025-51818
was published
Aug 21, 2025
Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command (...
High
Unreviewed
CVE-2025-41451
was published
Aug 22, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
CVE-2025-24293
was published
for
activestorage
(RubyGems)
Aug 14, 2025
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart...
Moderate
Unreviewed
CVE-2023-40146
was published
Apr 17, 2024
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49134
was published
Apr 9, 2024
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a...
High
Unreviewed
CVE-2025-48978
was published
Aug 21, 2025
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a...
Critical
Unreviewed
CVE-2025-24285
was published
Aug 21, 2025
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-6269
was published
Jun 23, 2024
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and...
Moderate
Unreviewed
CVE-2025-9244
was published
Aug 20, 2025
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email...
Moderate
Unreviewed
CVE-2025-57733
was published
Aug 20, 2025
A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts...
Moderate
Unreviewed
CVE-2025-50461
was published
Aug 19, 2025
An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData...
Moderate
Unreviewed
CVE-2025-52337
was published
Aug 19, 2025
screenshot-desktop vulnerable to command Injection via `format` option
Critical
CVE-2025-55294
was published
for
screenshot-desktop
(npm)
Aug 19, 2025
ProTip!
Advisories are also available from the
GraphQL API