GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,612 advisories
Filter by severity
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart...
Moderate
Unreviewed
CVE-2025-56426
was published
Oct 9, 2025
A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-11523
was published
Oct 9, 2025
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected...
Moderate
Unreviewed
CVE-2025-11490
was published
Oct 8, 2025
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element...
Moderate
Unreviewed
CVE-2025-11491
was published
Oct 8, 2025
A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function...
Moderate
Unreviewed
CVE-2025-11407
was published
Oct 7, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59736
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59739
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59740
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59737
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59741
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59738
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59735
was published
Oct 2, 2025
A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-9727
was published
Oct 1, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61045
was published
Oct 1, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61044
was published
Oct 1, 2025
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non...
High
Unreviewed
CVE-2025-41250
was published
Sep 29, 2025
A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue...
Moderate
Unreviewed
CVE-2025-11141
was published
Sep 29, 2025
A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne...
Moderate
Unreviewed
CVE-2025-11138
was published
Sep 29, 2025
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to...
Moderate
Unreviewed
CVE-2025-56383
was published
Sep 26, 2025
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the...
Moderate
Unreviewed
CVE-2025-55848
was published
Sep 26, 2025
This vulnerability allows attackers to execute arbitrary commands on the underlying system....
Critical
Unreviewed
CVE-2025-59817
was published
Sep 25, 2025
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system...
Critical
Unreviewed
CVE-2025-59815
was published
Sep 25, 2025
ProTip!
Advisories are also available from the
GraphQL API