GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-45491
was published
May 6, 2025
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet...
Critical
Unreviewed
CVE-2025-45042
was published
May 5, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Critical
Unreviewed
CVE-2025-2605
was published
May 2, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-6032
was published
Apr 30, 2025
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a...
High
Unreviewed
CVE-2025-24351
was published
Apr 30, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated...
Moderate
Unreviewed
CVE-2022-41871
was published
Apr 28, 2025
UNI-NMS-Lite is vulnerable to a command injection attack that could
allow an unauthenticated...
Critical
Unreviewed
CVE-2025-46271
was published
Apr 25, 2025
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection
attack that could allow an...
Critical
Unreviewed
CVE-2025-46272
was published
Apr 25, 2025
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user...
High
Unreviewed
CVE-2025-1976
was published
Apr 24, 2025
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-2773
was published
Apr 23, 2025
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution...
Critical
Unreviewed
CVE-2025-28038
was published
Apr 22, 2025
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution...
Critical
Unreviewed
CVE-2025-28039
was published
Apr 22, 2025
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution...
Critical
Unreviewed
CVE-2025-28035
was published
Apr 22, 2025
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution...
Critical
Unreviewed
CVE-2025-28036
was published
Apr 22, 2025
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a...
Critical
Unreviewed
CVE-2025-28037
was published
Apr 22, 2025
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu...
Critical
Unreviewed
CVE-2025-28034
was published
Apr 22, 2025
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute...
Moderate
Unreviewed
CVE-2025-43920
was published
Apr 20, 2025
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability...
Moderate
Unreviewed
CVE-2025-3816
was published
Apr 19, 2025
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-29042
was published
Apr 17, 2025
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-29043
was published
Apr 17, 2025
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-29041
was published
Apr 17, 2025
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-29040
was published
Apr 17, 2025
ProTip!
Advisories are also available from the
GraphQL API