GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,618
Maven
5,000+
npm
4,255
NuGet
760
pip
4,043
Pub
12
RubyGems
953
Rust
1,050
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,988 advisories
Filter by severity
A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue...
Moderate
Unreviewed
CVE-2025-11141
was published
Sep 29, 2025
A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne...
Moderate
Unreviewed
CVE-2025-11138
was published
Sep 29, 2025
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to...
Moderate
Unreviewed
CVE-2025-56383
was published
Sep 26, 2025
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the...
Moderate
Unreviewed
CVE-2025-55848
was published
Sep 26, 2025
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a...
Moderate
Unreviewed
CVE-2025-29157
was published
Sep 25, 2025
This vulnerability allows attackers to execute arbitrary commands on the underlying system....
Critical
Unreviewed
CVE-2025-59817
was published
Sep 25, 2025
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system...
Critical
Unreviewed
CVE-2025-59815
was published
Sep 25, 2025
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE...
Moderate
Unreviewed
CVE-2025-29155
was published
Sep 25, 2025
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker...
High
Unreviewed
CVE-2025-20334
was published
Sep 24, 2025
An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary...
Moderate
Unreviewed
CVE-2025-45326
was published
Sep 23, 2025
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code...
Moderate
Unreviewed
CVE-2025-29083
was published
Sep 23, 2025
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9,...
Moderate
Unreviewed
CVE-2025-57685
was published
Sep 22, 2025
A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown...
Moderate
Unreviewed
CVE-2025-10774
was published
Sep 22, 2025
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the...
Moderate
Unreviewed
CVE-2025-57296
was published
Sep 22, 2025
In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code...
High
Unreviewed
CVE-2025-43953
was published
Sep 22, 2025
A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the...
Low
Unreviewed
CVE-2025-10767
was published
Sep 22, 2025
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability...
Moderate
Unreviewed
CVE-2025-10775
was published
Sep 22, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail...
Moderate
Unreviewed
CVE-2025-59689
was published
Sep 19, 2025
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor...
Critical
Unreviewed
CVE-2025-10035
was published
Sep 19, 2025
A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10689
was published
Sep 18, 2025
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe...
High
Unreviewed
CVE-2025-57293
was published
Sep 18, 2025
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the...
Moderate
Unreviewed
CVE-2025-55911
was published
Sep 18, 2025
The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins...
High
Unreviewed
CVE-2023-49565
was published
Sep 18, 2025
ProTip!
Advisories are also available from the
GraphQL API