GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,101 advisories
Filter by severity
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS...
High
Unreviewed
CVE-2024-56132
was published
Feb 5, 2025
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the...
Moderate
Unreviewed
CVE-2025-8259
was published
Jul 28, 2025
An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6,...
Critical
Unreviewed
CVE-2025-50475
was published
Jul 31, 2025
Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8473
was published
Aug 1, 2025
An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically...
Critical
Unreviewed
CVE-2013-10049
was published
Aug 1, 2025
An authenticated OS command injection vulnerability exists in various Linksys router models ...
High
Unreviewed
CVE-2013-10058
was published
Aug 1, 2025
A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module...
High
Unreviewed
CVE-2013-10053
was published
Aug 1, 2025
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers
Critical
CVE-2025-54782
was published
for
@nestjs/devtools-integration
(npm)
Aug 1, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its...
High
Unreviewed
CVE-2025-36606
was published
Aug 4, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its...
High
Unreviewed
CVE-2025-36607
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
High
Unreviewed
CVE-2025-30099
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30096
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30097
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30098
was published
Aug 4, 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre...
Critical
Unreviewed
CVE-2025-54987
was published
Aug 5, 2025
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2025-51390
was published
Aug 4, 2025
Claude Code echo command allowed bypass of user approval prompt for command execution
High
CVE-2025-54795
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection....
High
Unreviewed
CVE-2025-43978
was published
Aug 5, 2025
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative...
High
Unreviewed
CVE-2012-10028
was published
Aug 5, 2025
Narcissus is vulnerable to remote code execution via improper input handling in its image...
Critical
Unreviewed
CVE-2012-10033
was published
Aug 5, 2025
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command...
High
Unreviewed
CVE-2012-10029
was published
Aug 5, 2025
An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated...
High
Unreviewed
CVE-2025-43979
was published
Aug 5, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8633
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8637
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8631
was published
Aug 6, 2025
ProTip!
Advisories are also available from the
GraphQL API