GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input...
High
Unreviewed
CVE-2025-2172
was published
Jun 23, 2025
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13...
Critical
Unreviewed
CVE-2025-34029
was published
Jun 20, 2025
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit....
Moderate
Unreviewed
CVE-2025-6193
was published
Jun 20, 2025
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due...
High
Unreviewed
CVE-2025-39240
was published
Jun 13, 2025
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated...
High
Unreviewed
CVE-2025-4230
was published
Jun 13, 2025
An unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands...
High
Unreviewed
CVE-2025-41663
was published
Jun 11, 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-31104
was published
Jun 10, 2025
An OS command injection vulnerability within the update functionality may allow an authenticated...
High
Unreviewed
CVE-2024-13089
was published
Jun 10, 2025
CWE-78: I Improper Neutralization of Special Elements used in an OS Command ('OS Command...
High
Unreviewed
CVE-2025-5743
was published
Jun 10, 2025
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
A command injection vulnerability has been reported to affect QHora. If an attacker gains local...
Low
Unreviewed
CVE-2024-13087
was published
Jun 6, 2025
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()`...
High
Unreviewed
CVE-2011-10007
was published
Jun 5, 2025
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05....
Moderate
Unreviewed
CVE-2025-5620
was published
Jun 5, 2025
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-5621
was published
Jun 5, 2025
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by...
Moderate
Unreviewed
CVE-2025-5573
was published
Jun 4, 2025
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5525
was published
Jun 3, 2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013...
Moderate
Unreviewed
CVE-2025-5447
was published
Jun 2, 2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013...
Moderate
Unreviewed
CVE-2025-5445
was published
Jun 2, 2025
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300,...
Moderate
Unreviewed
CVE-2025-5443
was published
Jun 2, 2025
A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-5444
was published
Jun 2, 2025
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited,...
High
Unreviewed
CVE-2025-41385
was published
May 30, 2025
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s...
Critical
Unreviewed
CVE-2025-48047
was published
May 29, 2025
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that...
Critical
Unreviewed
CVE-2025-5277
was published
May 28, 2025
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Critical
GHSA-phf6-hm3h-x8qp
was published
for
broadinstitute/cromwell
(GitHub Actions)
May 28, 2025
LLama-Index CLI OS command injection vulnerability
High
CVE-2025-1753
was published
for
llama-index-cli
(pip)
May 28, 2025
ProTip!
Advisories are also available from the
GraphQL API