GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,614 advisories
Filter by severity
Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input...
High
Unreviewed
CVE-2025-43948
was published
Apr 22, 2025
Directory Traversal vulnerability in forkosh Mime Tex before v.1.77 allows an attacker to execute...
High
Unreviewed
CVE-2024-40445
was published
Apr 22, 2025
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the...
Critical
Unreviewed
CVE-2025-29209
was published
Apr 21, 2025
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability...
Moderate
Unreviewed
CVE-2025-3816
was published
Apr 19, 2025
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
Moderate
Unreviewed
CVE-2024-46089
was published
Apr 18, 2025
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
High
Unreviewed
CVE-2025-43012
was published
Apr 17, 2025
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based...
Moderate
Unreviewed
CVE-2025-3729
was published
Apr 16, 2025
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload...
Moderate
Unreviewed
CVE-2024-40070
was published
Apr 16, 2025
An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part...
High
Unreviewed
CVE-2024-36842
was published
Apr 15, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a...
Moderate
Unreviewed
CVE-2025-28142
was published
Apr 15, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a...
Moderate
Unreviewed
CVE-2025-28143
was published
Apr 15, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a...
Moderate
Unreviewed
CVE-2025-28145
was published
Apr 15, 2025
Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller...
High
Unreviewed
CVE-2025-27083
was published
Apr 8, 2025
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1...
Critical
Unreviewed
CVE-2025-29062
was published
Apr 2, 2025
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2025-29063
was published
Apr 2, 2025
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot...
Moderate
Unreviewed
CVE-2025-26056
was published
Apr 1, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to...
Critical
Unreviewed
CVE-2024-54802
was published
Mar 31, 2025
A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to...
Moderate
Unreviewed
CVE-2025-3002
was published
Mar 31, 2025
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22941
was published
Mar 31, 2025
A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22939
was published
Mar 31, 2025
A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-2983
was published
Mar 31, 2025
An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all...
Low
Unreviewed
CVE-2024-9773
was published
Mar 27, 2025
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows...
Critical
Unreviewed
CVE-2024-55030
was published
Mar 25, 2025
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized...
High
Unreviewed
CVE-2025-29635
was published
Mar 25, 2025
A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13....
Moderate
Unreviewed
CVE-2025-2733
was published
Mar 25, 2025
ProTip!
Advisories are also available from the
GraphQL API