GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,457 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase...
Moderate
Unreviewed
CVE-2025-49250
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41362
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41365
was published
Jun 6, 2025
Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.
Critical
Unreviewed
CVE-2024-48070
was published
Nov 19, 2024
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Moderate
CVE-2025-35036
was published
for
org.hibernate.validator:hibernate-validator
(Maven)
Jun 3, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-23741
was published
Jan 28, 2024
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
High
Unreviewed
CVE-2025-25021
was published
Jun 3, 2025
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result...
Critical
Unreviewed
CVE-2025-32106
was published
Jun 3, 2025
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This...
Moderate
Unreviewed
CVE-2025-5151
was published
May 25, 2025
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted...
High
Unreviewed
CVE-2024-32358
was published
Apr 25, 2024
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in...
Critical
Unreviewed
CVE-2022-1609
was published
Jan 16, 2024
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-29505
was published
for
com.thoughtworks.xstream:xstream
(Maven)
May 18, 2021
Azure RTOS GUIX Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022...
High
Unreviewed
CVE-2022-35773
was published
Aug 10, 2022
Windows Network File System Remote Code Execution Vulnerability.
Critical
Unreviewed
CVE-2022-34715
was published
Aug 10, 2022
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID...
High
Unreviewed
CVE-2022-35767
was published
Aug 10, 2022
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID...
High
Unreviewed
CVE-2022-34714
was published
Aug 10, 2022
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-51360
was published
May 23, 2025
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker...
Moderate
Unreviewed
CVE-2023-37518
was published
Jan 30, 2024
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
Critical
Unreviewed
CVE-2022-41138
was published
Sep 21, 2022
Remote code execution via the `pretty` option.
Moderate
CVE-2021-21353
was published
for
pug
(npm)
Mar 3, 2021
Apache Pinot has Groovy Function support enabled by default
Critical
CVE-2022-26112
was published
for
org.apache.pinot:pinot
(Maven)
Sep 25, 2022
ProTip!
Advisories are also available from the
GraphQL API