GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,071 advisories
Filter by severity
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-45491
was published
May 6, 2025
goshs route not protected, allows command execution
Critical
CVE-2025-46816
was published
for
github.com/patrickhener/goshs
(Go)
May 6, 2025
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet...
Critical
Unreviewed
CVE-2025-45042
was published
May 5, 2025
TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the...
Critical
Unreviewed
CVE-2025-45800
was published
May 2, 2025
Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-44868
was published
May 2, 2025
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-44872
was published
May 2, 2025
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-44877
was published
May 2, 2025
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the...
Critical
Unreviewed
CVE-2025-29209
was published
Apr 21, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-ccj3-5p93-8p42
was published
for
surrealdb
(Rust)
Apr 11, 2025
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2025-29063
was published
Apr 2, 2025
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1...
Critical
Unreviewed
CVE-2025-29062
was published
Apr 2, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to...
Critical
Unreviewed
CVE-2024-54802
was published
Mar 31, 2025
A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22939
was published
Mar 31, 2025
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22941
was published
Mar 31, 2025
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows...
Critical
Unreviewed
CVE-2024-55030
was published
Mar 25, 2025
Duplicate Advisory: D-Tale Command Injection vulnerability
Critical
CVE-2025-0655
was published
for
dtale
(pip)
Mar 20, 2025
•
withdrawn
Withdrawn Advisory: Dask Vulnerable to Command Injection
Critical
CVE-2024-10096
was published
for
dask
(pip)
Mar 20, 2025
•
withdrawn
Horovod Vulnerable to Command Injection
Critical
CVE-2024-10190
was published
for
horovod
(pip)
Mar 20, 2025
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of...
Critical
Unreviewed
CVE-2024-13871
was published
Mar 12, 2025
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform...
Critical
Unreviewed
CVE-2025-25632
was published
Mar 5, 2025
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand...
Critical
Unreviewed
CVE-2025-25675
was published
Feb 21, 2025
DocsGPT Allows Remote Code Execution
Critical
CVE-2025-0868
was published
for
docsgpt
(npm)
Feb 20, 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2025-22630
was published
Feb 14, 2025
ProTip!
Advisories are also available from the
GraphQL API