GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,102 advisories
Filter by severity
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the...
High
Unreviewed
CVE-2012-3001
was published
May 17, 2022
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border...
High
Unreviewed
CVE-2013-4781
was published
May 17, 2022
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute...
High
Unreviewed
CVE-2012-4177
was published
May 17, 2022
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated...
High
Unreviewed
CVE-2022-38387
was published
Nov 12, 2022
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3...
High
Unreviewed
CVE-2013-4983
was published
May 17, 2022
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration...
High
Unreviewed
CVE-2013-3578
was published
May 17, 2022
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password,...
Moderate
Unreviewed
CVE-2020-14342
was published
May 24, 2022
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and...
High
Unreviewed
CVE-2013-2578
was published
May 17, 2022
If exploited, this command injection vulnerability could allow remote attackers to execute...
Critical
Unreviewed
CVE-2018-19950
was published
May 24, 2022
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to...
Moderate
Unreviewed
CVE-2012-4108
was published
May 17, 2022
The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code,...
Moderate
Unreviewed
CVE-2013-5703
was published
May 17, 2022
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the...
High
Unreviewed
CVE-2021-3725
was published
Dec 1, 2021
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via...
High
Unreviewed
CVE-2013-3365
was published
May 17, 2022
ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to...
High
Unreviewed
CVE-2013-3576
was published
May 17, 2022
The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR...
High
Unreviewed
CVE-2013-5946
was published
May 17, 2022
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote...
High
Unreviewed
CVE-2014-0356
was published
May 17, 2022
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote...
High
Unreviewed
CVE-2013-1616
was published
May 17, 2022
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via...
High
Unreviewed
CVE-2013-2642
was published
May 17, 2022
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute...
High
Unreviewed
CVE-2014-2874
was published
May 17, 2022
Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via...
High
Unreviewed
CVE-2014-0359
was published
May 17, 2022
The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows...
Moderate
Unreviewed
CVE-2014-2565
was published
May 17, 2022
A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical....
High
Unreviewed
CVE-2021-4242
was published
Nov 30, 2022
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary...
High
Unreviewed
CVE-2014-2707
was published
May 17, 2022
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute...
High
Unreviewed
CVE-2014-2935
was published
May 17, 2022
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute...
High
Unreviewed
CVE-2013-5758
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API