GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
635 advisories
Filter by severity
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded...
Critical
Unreviewed
CVE-2025-3114
was published
Apr 9, 2025
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a...
Critical
Unreviewed
CVE-2025-31330
was published
Apr 8, 2025
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function...
Critical
Unreviewed
CVE-2025-27429
was published
Apr 8, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a...
Critical
Unreviewed
CVE-2025-28146
was published
Apr 4, 2025
The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all...
Critical
Unreviewed
CVE-2024-13645
was published
Apr 4, 2025
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2025-29064
was published
Apr 3, 2025
Netwrix Password Secure through 9.2 allows command injection.
Critical
Unreviewed
CVE-2025-26818
was published
Apr 3, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets...
Critical
Unreviewed
CVE-2025-30580
was published
Apr 1, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RomethemeKit...
Critical
Unreviewed
CVE-2025-30911
was published
Apr 1, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54804
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54805
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi...
Critical
Unreviewed
CVE-2024-54806
was published
Mar 31, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in...
Critical
Unreviewed
CVE-2024-54807
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54803
was published
Mar 31, 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case...
Critical
Unreviewed
CVE-2025-29306
was published
Mar 27, 2025
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when...
Critical
Unreviewed
CVE-2025-26003
was published
Mar 26, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text...
Critical
Unreviewed
CVE-2025-28893
was published
Mar 26, 2025
A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to...
Critical
Unreviewed
CVE-2024-55028
was published
Mar 25, 2025
An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to...
Critical
Unreviewed
CVE-2024-48818
was published
Mar 25, 2025
An improper control of generation of code ('Code Injection') vulnerability in the...
Critical
Unreviewed
CVE-2024-45480
was published
Mar 25, 2025
A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an...
Critical
Unreviewed
CVE-2024-8581
was published
Mar 20, 2025
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to...
Critical
Unreviewed
CVE-2024-57061
was published
Mar 19, 2025
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7...
Critical
Unreviewed
CVE-2025-29401
was published
Mar 19, 2025
An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters...
Critical
Unreviewed
CVE-2024-55551
was published
Mar 19, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Fresh...
Critical
Unreviewed
CVE-2025-26936
was published
Mar 10, 2025
ProTip!
Advisories are also available from the
GraphQL API