GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,102 advisories
Filter by severity
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP,...
High
Unreviewed
CVE-2025-25893
was published
Feb 19, 2025
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
Critical
Unreviewed
CVE-2021-46686
was published
Feb 18, 2025
Implementation of the Simple Network
Management Protocol (SNMP) operating on the Brocade 6547 ...
High
Unreviewed
CVE-2024-5461
was published
Feb 15, 2025
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0...
High
Unreviewed
CVE-2024-55904
was published
Feb 14, 2025
mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote...
Critical
Unreviewed
CVE-2025-25067
was published
Feb 14, 2025
A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an...
High
Unreviewed
CVE-2025-0110
was published
Feb 12, 2025
A flaw was found in the Emacs text editor. Improper handling of custom "man" URI schemes allows...
High
Unreviewed
CVE-2025-1244
was published
Feb 12, 2025
A improper neutralization of special elements used in an os command ('os command injection') in...
Moderate
Unreviewed
CVE-2024-50569
was published
Feb 11, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2024-40584
was published
Feb 11, 2025
An improper neutralization of special elements used in an os command ('os command injection') in...
High
Unreviewed
CVE-2024-50567
was published
Feb 11, 2025
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote...
Critical
Unreviewed
CVE-2024-47908
was published
Feb 11, 2025
OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS...
High
Unreviewed
CVE-2024-8684
was published
Feb 10, 2025
An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to...
High
Unreviewed
CVE-2024-57357
was published
Feb 8, 2025
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker...
Critical
Unreviewed
CVE-2024-51450
was published
Feb 6, 2025
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command...
High
Unreviewed
CVE-2025-20029
was published
Feb 5, 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS...
High
Unreviewed
CVE-2024-56132
was published
Feb 5, 2025
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy...
Moderate
Unreviewed
CVE-2025-25039
was published
Feb 4, 2025
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability...
High
Unreviewed
CVE-2024-23690
was published
Feb 4, 2025
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI...
High
Unreviewed
CVE-2024-40890
was published
Feb 4, 2025
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the...
High
Unreviewed
CVE-2024-40891
was published
Feb 4, 2025
An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic...
Moderate
Unreviewed
CVE-2024-53942
was published
Feb 3, 2025
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone...
Critical
Unreviewed
CVE-2024-53584
was published
Jan 31, 2025
Affected products contain a vulnerability in the device cloud rpc command handling process that...
Critical
Unreviewed
CVE-2025-0680
was published
Jan 30, 2025
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email...
Critical
Unreviewed
CVE-2025-20061
was published
Jan 29, 2025
ProTip!
Advisories are also available from the
GraphQL API