GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,328
Maven
5,000+
npm
3,965
NuGet
712
pip
3,745
Pub
12
RubyGems
921
Rust
974
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,120 advisories
Filter by severity
Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D...
Critical
Unreviewed
CVE-2021-46315
was published
Feb 18, 2022
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript...
Critical
Unreviewed
CVE-2021-3781
was published
Feb 17, 2022
An OS command injection was found in SecuwaySSL, when special characters injection on execute...
Critical
Unreviewed
CVE-2021-26616
was published
Feb 11, 2022
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers...
Critical
Unreviewed
CVE-2022-20708
was published
Feb 11, 2022
OS Command Injection in install-package
Critical
CVE-2020-7629
was published
for
install-package
(npm)
Feb 10, 2022
OS Command Injection in git-add-remote
Critical
CVE-2020-7630
was published
for
git-add-remote
(npm)
Feb 10, 2022
OS Command Injection in node-key-sender
Critical
CVE-2020-7627
was published
for
node-key-sender
(npm)
Feb 10, 2022
Withdrawn Advisory: OS Command Injection in effect
Critical
CVE-2020-7624
was published
for
effect
(npm)
Feb 10, 2022
•
withdrawn
karma-mojo enables OS Command Injection
Critical
CVE-2020-7626
was published
for
karma-mojo
(npm)
Feb 10, 2022
Code injection in @rkesters/gnuplot
Critical
CVE-2021-29369
was published
for
@rkesters/gnuplot
(npm)
Feb 10, 2022
OS Command Injection in strong-nginx-controller
Critical
CVE-2020-7621
was published
for
strong-nginx-controller
(npm)
Feb 10, 2022
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar...
Critical
Unreviewed
CVE-2021-29393
was published
Feb 10, 2022
The affected product is vulnerable to an authenticated OS command injection, which may allow an...
Critical
Unreviewed
CVE-2022-0365
was published
Feb 10, 2022
push-dir Enables OS Command Injection
Critical
CVE-2019-10803
was published
for
push-dir
(npm)
Feb 9, 2022
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-44882
was published
Feb 8, 2022
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were...
Critical
Unreviewed
CVE-2021-44880
was published
Feb 8, 2022
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-44881
was published
Feb 8, 2022
An OS command injection vulnerability exists in the device network settings functionality of...
Critical
Unreviewed
CVE-2021-40409
was published
Jan 29, 2022
An OS command injection vulnerability exists in the device network settings functionality of...
Critical
Unreviewed
CVE-2021-40408
was published
Jan 29, 2022
An OS command injection vulnerability exists in the device network settings functionality of...
Critical
Unreviewed
CVE-2021-40407
was published
Jan 29, 2022
Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks
Critical
CVE-2021-21386
was published
for
APKLeaks
(pip)
Jan 21, 2022
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability...
Critical
Unreviewed
CVE-2021-33962
was published
Jan 15, 2022
OS Command Injection in diskusage-ng
Critical
CVE-2020-7631
was published
for
diskusage-ng
(npm)
Jan 7, 2022
ProTip!
Advisories are also available from the
GraphQL API