GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,071 advisories
Filter by severity
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided...
Critical
Unreviewed
CVE-2023-22671
was published
Jan 6, 2023
exec-local-bin vulnerable to Command Injection
Critical
CVE-2022-25923
was published
for
exec-local-bin
(npm)
Jan 6, 2023
A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by...
Critical
Unreviewed
CVE-2021-4304
was published
Jan 5, 2023
In Boa, there is a possible command injection due to improper input validation. This could lead...
Critical
Unreviewed
CVE-2022-32665
was published
Jan 3, 2023
The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which...
Critical
Unreviewed
CVE-2023-0039
was published
Jan 3, 2023
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some...
Critical
Unreviewed
CVE-2017-20156
was published
Dec 31, 2022
Apache Kylin vulnerable to Command injection by Diagnosis Controller
Critical
CVE-2022-44621
was published
for
org.apache.kylin:kylin-server-base
(Maven)
Dec 30, 2022
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-45717
was published
Dec 23, 2022
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-46642
was published
Dec 23, 2022
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-46641
was published
Dec 23, 2022
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac...
Critical
Unreviewed
CVE-2022-46538
was published
Dec 20, 2022
Apache Airflow Hive Provider vulnerable to Command Injection
Critical
CVE-2022-46421
was published
for
apache-airflow-providers-apache-hive
(pip)
Dec 20, 2022
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-46631
was published
Dec 16, 2022
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-46634
was published
Dec 16, 2022
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI...
Critical
Unreviewed
CVE-2022-31702
was published
Dec 14, 2022
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-44832
was published
Dec 14, 2022
cycle-import-check vulnerable to Command Injection
Critical
CVE-2022-24377
was published
for
cycle-import-check
(npm)
Dec 14, 2022
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-45005
was published
Dec 13, 2022
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and...
Critical
Unreviewed
CVE-2022-46404
was published
Dec 13, 2022
There is a command injection vulnerability that could lead to unauthenticated remote code...
Critical
Unreviewed
CVE-2022-37897
was published
Dec 12, 2022
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-45506
was published
Dec 8, 2022
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-45497
was published
Dec 8, 2022
A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16....
Critical
Unreviewed
CVE-2022-4364
was published
Dec 8, 2022
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a...
Critical
Unreviewed
CVE-2022-45025
was published
Dec 7, 2022
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-44928
was published
Dec 2, 2022
ProTip!
Advisories are also available from the
GraphQL API