GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,996 advisories
Filter by severity
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command...
Critical
Unreviewed
CVE-2023-45498
was published
Oct 27, 2023
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters...
High
Unreviewed
CVE-2023-4797
was published
Jan 16, 2024
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an...
Moderate
Unreviewed
CVE-2025-5265
was published
May 27, 2025
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-47176
was published
Jun 10, 2025
Improper Neutralization of Special Elements in the chromium_path variable may allow OS command...
High
Unreviewed
CVE-2025-4678
was published
Jun 10, 2025
Improper Neutralization of Special Elements in the backup name field may allow OS command...
High
Unreviewed
CVE-2025-4653
was published
Jun 10, 2025
@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE
High
CVE-2024-34347
was published
for
@hoppscotch/cli
(npm)
Apr 22, 2024
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300,...
Moderate
Unreviewed
CVE-2025-5443
was published
Jun 2, 2025
A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-5444
was published
Jun 2, 2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013...
Moderate
Unreviewed
CVE-2025-5445
was published
Jun 2, 2025
A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical....
Moderate
Unreviewed
CVE-2025-5763
was published
Jun 6, 2025
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5606
was published
Jun 4, 2025
A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta....
Moderate
Unreviewed
CVE-2025-5952
was published
Jun 10, 2025
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by...
Moderate
Unreviewed
CVE-2025-5573
was published
Jun 4, 2025
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5525
was published
Jun 3, 2025
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-5621
was published
Jun 5, 2025
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05....
Moderate
Unreviewed
CVE-2025-5620
was published
Jun 5, 2025
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an...
Moderate
Unreviewed
CVE-2025-20278
was published
Jun 4, 2025
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2025-27954
was published
Jun 2, 2025
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical....
Moderate
Unreviewed
CVE-2025-5571
was published
Jun 4, 2025
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2023-51812
was published
Jan 4, 2024
In engineermode service, there is a possible command injection due to improper input validation....
Moderate
Unreviewed
CVE-2025-31710
was published
Jun 3, 2025
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2025-27953
was published
Jun 2, 2025
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452....
Moderate
Unreviewed
CVE-2024-0579
was published
Jan 16, 2024
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-48842
was published
Dec 1, 2023
ProTip!
Advisories are also available from the
GraphQL API