GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,102 advisories
Filter by severity
Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability...
High
Unreviewed
CVE-2024-8808
was published
Nov 22, 2024
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5717
was published
Nov 22, 2024
Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2024-6247
was published
Nov 22, 2024
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5719
was published
Nov 22, 2024
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5720
was published
Nov 22, 2024
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used...
Critical
Unreviewed
CVE-2024-52723
was published
Nov 22, 2024
An OS command injection vulnerability has been reported to affect several product versions. If...
High
Unreviewed
CVE-2024-48861
was published
Nov 22, 2024
An OS command injection vulnerability has been reported to affect several product versions. If...
Critical
Unreviewed
CVE-2024-48860
was published
Nov 22, 2024
D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function...
Critical
Unreviewed
CVE-2024-51151
was published
Nov 22, 2024
OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent...
High
Unreviewed
CVE-2024-31408
was published
Nov 22, 2024
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
High
Unreviewed
CVE-2024-48895
was published
Nov 20, 2024
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20...
High
Unreviewed
CVE-2024-51503
was published
Nov 19, 2024
Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library ...
High
Unreviewed
CVE-2024-11003
was published
Nov 19, 2024
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
Low
CVE-2024-52587
was published
for
step-security/harden-runner
(GitHub Actions)
Nov 18, 2024
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS...
Moderate
Unreviewed
CVE-2024-9474
was published
Nov 18, 2024
An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP...
High
Unreviewed
CVE-2024-44759
was published
Nov 15, 2024
A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to...
High
Unreviewed
CVE-2024-24431
was published
Nov 15, 2024
A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to...
Critical
Unreviewed
CVE-2023-20036
was published
Nov 15, 2024
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web...
Moderate
Unreviewed
CVE-2022-20871
was published
Nov 15, 2024
A vulnerability in the web-based management interface and in the API subsystem of Cisco ...
Moderate
Unreviewed
CVE-2022-20652
was published
Nov 15, 2024
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an...
High
Unreviewed
CVE-2022-20655
was published
Nov 15, 2024
LibreNMS has an Authenticated OS Command Injection
Critical
CVE-2024-51092
was published
for
librenms/librenms
(Composer)
Nov 15, 2024
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote...
Critical
Unreviewed
CVE-2024-11120
was published
Nov 15, 2024
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method...
Critical
Unreviewed
CVE-2024-4343
was published
Nov 14, 2024
ProTip!
Advisories are also available from the
GraphQL API