GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,683 advisories
Filter by severity
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126...
Moderate
Unreviewed
CVE-2025-2717
was published
Mar 25, 2025
Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt...
Moderate
Unreviewed
CVE-2025-27804
was published
May 21, 2025
AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
Moderate
Unreviewed
CVE-2024-42922
was published
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows command injections
Moderate
CVE-2025-48204
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-3881
was published
May 22, 2025
eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-3883
was published
May 22, 2025
eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution...
High
Unreviewed
CVE-2025-3882
was published
May 22, 2025
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3...
High
Unreviewed
CVE-2022-40785
was published
Sep 27, 2022
On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump...
High
Unreviewed
CVE-2023-34873
was published
May 23, 2025
Insufficient input sanitization in ejson2env
Moderate
CVE-2025-48069
was published
for
ejson2env
(RubyGems)
May 21, 2025
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Critical
GHSA-phf6-hm3h-x8qp
was published
for
broadinstitute/cromwell
(GitHub Actions)
May 28, 2025
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16...
High
Unreviewed
CVE-2025-0528
was published
Jan 17, 2025
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that...
Critical
Unreviewed
CVE-2025-5277
was published
May 28, 2025
LLama-Index CLI OS command injection vulnerability
High
CVE-2025-1753
was published
for
llama-index-cli
(pip)
May 28, 2025
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37882
was published
Sep 21, 2022
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37878
was published
Sep 21, 2022
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote...
High
Unreviewed
CVE-2022-37880
was published
Sep 21, 2022
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
Critical
Unreviewed
CVE-2025-26817
was published
Apr 3, 2025
MantisBT Remote Code Execution
High
CVE-2019-15715
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s...
Critical
Unreviewed
CVE-2025-48047
was published
May 29, 2025
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited,...
High
Unreviewed
CVE-2025-41385
was published
May 30, 2025
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
ASUS RT-AX55 v3.0.0.4.386.51598 was discovered to contain an authenticated command injection...
High
Unreviewed
CVE-2023-39780
was published
Sep 11, 2023
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-48842
was published
Dec 1, 2023
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools...
Moderate
Unreviewed
CVE-2020-27298
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API