GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,989 advisories
Filter by severity
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting ...
High
Unreviewed
CVE-2024-55544
was published
Dec 10, 2024
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP...
Critical
Unreviewed
CVE-2024-55547
was published
Dec 10, 2024
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core...
High
Unreviewed
CVE-2024-53919
was published
Dec 10, 2024
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-12358
was published
Dec 9, 2024
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If...
Critical
Unreviewed
CVE-2024-50388
was published
Dec 6, 2024
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management...
High
Unreviewed
CVE-2024-51771
was published
Dec 3, 2024
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote...
Moderate
Unreviewed
CVE-2024-53672
was published
Dec 3, 2024
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface...
Moderate
Unreviewed
CVE-2024-51772
was published
Dec 3, 2024
An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote...
High
Unreviewed
CVE-2024-51114
was published
Dec 3, 2024
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker...
High
Unreviewed
CVE-2024-29404
was published
Dec 3, 2024
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for...
High
Unreviewed
CVE-2024-11013
was published
Nov 29, 2024
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv...
Moderate
Unreviewed
CVE-2024-48747
was published
Nov 26, 2024
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of...
High
Unreviewed
CVE-2024-48288
was published
Nov 26, 2024
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the...
Moderate
Unreviewed
CVE-2024-11320
was published
Nov 26, 2024
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor...
High
Unreviewed
CVE-2024-38831
was published
Nov 26, 2024
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in...
Moderate
Unreviewed
CVE-2024-53333
was published
Nov 26, 2024
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and...
Moderate
Unreviewed
CVE-2024-11659
was published
Nov 25, 2024
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and...
Moderate
Unreviewed
CVE-2024-11658
was published
Nov 25, 2024
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT...
Moderate
Unreviewed
CVE-2024-11655
was published
Nov 25, 2024
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500...
Moderate
Unreviewed
CVE-2024-11656
was published
Nov 25, 2024
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC...
Moderate
Unreviewed
CVE-2024-11657
was published
Nov 25, 2024
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has...
Moderate
Unreviewed
CVE-2024-11653
was published
Nov 25, 2024
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and...
Moderate
Unreviewed
CVE-2024-11654
was published
Nov 25, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-11665
was published
Nov 25, 2024
virtualenv allows command injection through activation scripts for a virtual environment
High
CVE-2024-53899
was published
for
virtualenv
(pip)
Nov 24, 2024
ProTip!
Advisories are also available from the
GraphQL API