GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,102 advisories
Filter by severity
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3...
High
Unreviewed
CVE-2022-40785
was published
Sep 27, 2022
On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump...
High
Unreviewed
CVE-2023-34873
was published
May 23, 2025
Insufficient input sanitization in ejson2env
Moderate
CVE-2025-48069
was published
for
ejson2env
(RubyGems)
May 21, 2025
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Critical
GHSA-phf6-hm3h-x8qp
was published
for
broadinstitute/cromwell
(GitHub Actions)
May 28, 2025
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16...
High
Unreviewed
CVE-2025-0528
was published
Jan 17, 2025
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that...
Critical
Unreviewed
CVE-2025-5277
was published
May 28, 2025
LLama-Index CLI OS command injection vulnerability
High
CVE-2025-1753
was published
for
llama-index-cli
(pip)
May 28, 2025
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37882
was published
Sep 21, 2022
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37880
was published
Sep 21, 2022
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37878
was published
Sep 21, 2022
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
Critical
Unreviewed
CVE-2025-26817
was published
Apr 3, 2025
MantisBT Remote Code Execution
High
CVE-2019-15715
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s...
Critical
Unreviewed
CVE-2025-48047
was published
May 29, 2025
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited,...
High
Unreviewed
CVE-2025-41385
was published
May 30, 2025
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-48842
was published
Dec 1, 2023
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools...
Moderate
Unreviewed
CVE-2020-27298
was published
May 24, 2022
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()`...
High
Unreviewed
CVE-2011-10007
was published
Jun 5, 2025
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05....
Moderate
Unreviewed
CVE-2025-5620
was published
Jun 5, 2025
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5525
was published
Jun 3, 2025
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-5621
was published
Jun 5, 2025
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by...
Moderate
Unreviewed
CVE-2025-5573
was published
Jun 4, 2025
CWE-78: I Improper Neutralization of Special Elements used in an OS Command ('OS Command...
High
Unreviewed
CVE-2025-5743
was published
Jun 10, 2025
An OS command injection vulnerability within the update functionality may allow an authenticated...
High
Unreviewed
CVE-2024-13089
was published
Jun 10, 2025
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300,...
Moderate
Unreviewed
CVE-2025-5443
was published
Jun 2, 2025
A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-5444
was published
Jun 2, 2025
ProTip!
Advisories are also available from the
GraphQL API