GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote...
High
Unreviewed
CVE-2017-6334
was published
May 13, 2022
Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less...
High
Unreviewed
CVE-2017-6224
was published
May 13, 2022
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible...
Critical
Unreviewed
CVE-2017-6182
was published
May 13, 2022
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code...
High
Unreviewed
CVE-2017-6087
was published
May 13, 2022
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10...
Critical
Unreviewed
CVE-2017-4053
was published
May 13, 2022
The Lenovo Service Framework Android application executes some system commands without proper...
Critical
Unreviewed
CVE-2017-3761
was published
May 13, 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent:...
High
Unreviewed
CVE-2017-3506
was published
May 13, 2022
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix...
High
Unreviewed
CVE-2017-2824
was published
May 13, 2022
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before...
Critical
Unreviewed
CVE-2017-18044
was published
May 13, 2022
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands...
High
Unreviewed
CVE-2017-17758
was published
May 13, 2022
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands...
High
Unreviewed
CVE-2017-17757
was published
May 13, 2022
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute...
High
Unreviewed
CVE-2017-16960
was published
May 13, 2022
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute...
High
Unreviewed
CVE-2017-16957
was published
May 13, 2022
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute...
High
Unreviewed
CVE-2017-16958
was published
May 13, 2022
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14...
High
Unreviewed
CVE-2017-17020
was published
May 13, 2022
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05...
High
Unreviewed
CVE-2017-16923
was published
May 13, 2022
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell...
Critical
Unreviewed
CVE-2017-16926
was published
May 13, 2022
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell...
High
Unreviewed
CVE-2017-16666
was published
May 13, 2022
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection...
High
Unreviewed
CVE-2017-15924
was published
May 13, 2022
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because...
Critical
Unreviewed
CVE-2017-15226
was published
May 13, 2022
DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001...
High
Unreviewed
CVE-2017-14705
was published
May 13, 2022
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV....
Critical
Unreviewed
CVE-2017-14429
was published
May 13, 2022
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified...
Critical
Unreviewed
CVE-2017-14100
was published
May 13, 2022
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell...
High
Unreviewed
CVE-2017-13713
was published
May 13, 2022
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1...
Critical
Unreviewed
CVE-2017-11588
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API