GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,992 advisories
Filter by severity
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2024-31811
was published
Apr 8, 2024
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which...
High
Unreviewed
CVE-2024-30891
was published
Apr 5, 2024
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi...
Critical
Unreviewed
CVE-2024-27981
was published
Apr 5, 2024
pgAdmin Remote Code Execution (RCE) vulnerability
High
CVE-2024-3116
was published
for
pgadmin4
(pip)
Apr 4, 2024
A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS...
High
Unreviewed
CVE-2024-3273
was published
Apr 4, 2024
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-30572
was published
Apr 3, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-27972
was published
Apr 3, 2024
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially...
High
Unreviewed
CVE-2024-22246
was published
Apr 2, 2024
There is a command injection vulnerability in some Hikvision NVRs. This could allow an...
High
Unreviewed
CVE-2024-29949
was published
Apr 2, 2024
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId...
Moderate
Unreviewed
CVE-2024-29435
was published
Apr 1, 2024
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat...
Critical
Unreviewed
CVE-2023-41724
was published
Mar 31, 2024
aliyundrive-webdav vulnerable to Command Injection
High
CVE-2024-29640
was published
for
aliyundrive-webdav
(pip)
Mar 29, 2024
Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function...
High
Unreviewed
CVE-2024-30637
was published
Mar 29, 2024
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An...
High
Unreviewed
CVE-2024-25955
was published
Mar 28, 2024
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web...
High
Unreviewed
CVE-2024-2947
was published
Mar 28, 2024
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An...
High
Unreviewed
CVE-2024-25946
was published
Mar 28, 2024
A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected...
Moderate
Unreviewed
CVE-2024-3009
was published
Mar 28, 2024
A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-2991
was published
Mar 27, 2024
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub in the...
High
Unreviewed
CVE-2024-29946
was published
Mar 27, 2024
Gradio's CI vulnerable to Command Injection
High
CVE-2024-1540
was published
for
gradio
(pip)
Mar 27, 2024
•
withdrawn
A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected...
Moderate
Unreviewed
CVE-2024-2982
was published
Mar 27, 2024
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter...
Critical
Unreviewed
CVE-2024-28545
was published
Mar 26, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Wake DMCUB...
High
Unreviewed
CVE-2023-52624
was published
Mar 26, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-24897
was published
Mar 25, 2024
ProTip!
Advisories are also available from the
GraphQL API