GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43911
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36567
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36569
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36566
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43908
was published
Oct 7, 2025
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows...
High
Unreviewed
CVE-2025-57457
was published
Oct 8, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2025-47212
was published
Oct 3, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with...
High
Unreviewed
CVE-2025-10239
was published
Oct 9, 2025
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS...
Moderate
Unreviewed
CVE-2025-60006
was published
Oct 9, 2025
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to...
High
Unreviewed
CVE-2016-15047
was published
Oct 9, 2025
A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0....
Moderate
Unreviewed
CVE-2025-2701
was published
Mar 24, 2025
EMCLI contains a high severity vulnerability where improper neutralization of special elements...
High
Unreviewed
CVE-2025-0636
was published
Oct 13, 2025
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform...
Critical
Unreviewed
CVE-2025-9976
was published
Oct 13, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10243
was published
Oct 14, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10242
was published
Oct 14, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10985
was published
Oct 14, 2025
Two improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2025-47856
was published
Oct 14, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-5946
was published
Oct 14, 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2024-48891
was published
Oct 14, 2025
A user with specific node group editing permissions and a specially crafted class parameter could...
High
Unreviewed
CVE-2025-5459
was published
Jun 26, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Critical
Unreviewed
CVE-2025-52906
was published
Sep 24, 2025
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the...
High
Unreviewed
CVE-2025-34227
was published
Sep 25, 2025
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7304
was published
Oct 15, 2025
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7311
was published
Oct 15, 2025
ProTip!
Advisories are also available from the
GraphQL API