GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,328
Maven
5,000+
npm
3,965
NuGet
712
pip
3,745
Pub
12
RubyGems
921
Rust
974
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,120 advisories
Filter by severity
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and ...
Critical
Unreviewed
CVE-2021-3727
was published
Dec 1, 2021
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It...
Critical
Unreviewed
CVE-2020-7879
was published
Dec 1, 2021
A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited,...
Critical
Unreviewed
CVE-2021-38685
was published
Nov 27, 2021
Vulnerability in packageCmd function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36378
was published
for
aaptjs
(npm)
Nov 2, 2021
Vulnerability in remove function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36379
was published
for
aaptjs
(npm)
Nov 2, 2021
Vulnerability in dump function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36377
was published
for
aaptjs
(npm)
Nov 2, 2021
Vulnerability in list function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36376
was published
for
aaptjs
(npm)
Nov 2, 2021
Vulnerability in singleCrunch function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36381
was published
for
aaptjs
(npm)
Nov 1, 2021
Vulnerability in crunch function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36380
was published
for
aaptjs
(npm)
Nov 1, 2021
Command injection leading to Remote Code Execution in Apache Storm
Critical
CVE-2021-38294
was published
for
org.apache.storm:storm
(Maven)
Oct 27, 2021
OS Command Injection in node-opencv
Critical
CVE-2019-10061
was published
for
opencv
(npm)
Oct 12, 2021
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ZMarkdown
Critical
GHSA-2c83-wfv3-q25f
was published
for
rebber
(npm)
Sep 7, 2021
Bash command injection in Apache Zeppelin
Critical
CVE-2019-10095
was published
for
org.apache.zeppelin:zeppelin
(Maven)
Sep 7, 2021
remote code execution via git repo provider
Critical
CVE-2021-39159
was published
for
binderhub
(pip)
Aug 30, 2021
OS command injection in ripgrep
Critical
CVE-2021-3013
was published
for
grep-cli
(Rust)
Aug 5, 2021
OS Command Injection in OpenTSDB
Critical
CVE-2020-35476
was published
for
net.opentsdb:opentsdb
(Maven)
Aug 2, 2021
OS Command Injection in Locutus
Critical
CVE-2020-13619
was published
for
locutus
(npm)
Jul 26, 2021
elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE
Critical
CVE-2021-32682
was published
for
studio-42/elfinder
(Composer)
Jun 16, 2021
apiconnect-cli-plugins vulnerable to OS Command Injection
Critical
CVE-2020-7633
was published
for
apiconnect-cli-plugins
(npm)
May 24, 2021
OS Command Injection in wifiscanner
Critical
CVE-2020-15362
was published
for
wifiscanner
(npm)
May 17, 2021
OS Command Injection in pomelo-monitor
Critical
CVE-2020-7620
was published
for
pomelo-monitor
(npm)
May 10, 2021
Command injection in get-git-data
Critical
CVE-2020-7619
was published
for
get-git-data
(npm)
May 10, 2021
OS Command Injection in pulverizr
Critical
CVE-2020-7604
was published
for
pulverizr
(npm)
May 7, 2021
ProTip!
Advisories are also available from the
GraphQL API