GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
902 advisories
Filter by severity
Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.
Critical
Unreviewed
CVE-2024-48070
was published
Nov 19, 2024
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-23741
was published
Jan 28, 2024
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result...
Critical
Unreviewed
CVE-2025-32106
was published
Jun 3, 2025
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in...
Critical
Unreviewed
CVE-2022-1609
was published
Jan 16, 2024
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
Windows Network File System Remote Code Execution Vulnerability.
Critical
Unreviewed
CVE-2022-34715
was published
Aug 10, 2022
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-51360
was published
May 23, 2025
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
Critical
Unreviewed
CVE-2022-41138
was published
Sep 21, 2022
Apache Pinot has Groovy Function support enabled by default
Critical
CVE-2022-26112
was published
for
org.apache.pinot:pinot
(Maven)
Sep 25, 2022
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE)...
Critical
Unreviewed
CVE-2023-48085
was published
Dec 14, 2023
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0...
Critical
Unreviewed
CVE-2025-44881
was published
May 20, 2025
Langroid has a Code Injection vulnerability in TableChatAgent
Critical
CVE-2025-46724
was published
for
langroid
(pip)
May 20, 2025
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the...
Critical
Unreviewed
CVE-2025-26845
was published
May 8, 2025
Dolibarr vulnerable to Eval Injection
Critical
CVE-2022-40871
was published
for
dolibarr/dolibarr
(Composer)
Oct 12, 2022
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
org.apache.iotdb:iotdb-core
(Maven)
May 14, 2025
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target...
Critical
Unreviewed
CVE-2025-32363
was published
May 14, 2025
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code...
Critical
Unreviewed
CVE-2015-2079
was published
Apr 28, 2025
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2025-45857
was published
May 13, 2025
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2022-41544
was published
Oct 18, 2022
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin...
Critical
Unreviewed
CVE-2025-44022
was published
May 12, 2025
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because...
Critical
Unreviewed
CVE-2025-46661
was published
Apr 28, 2025
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a...
Critical
Unreviewed
CVE-2025-29509
was published
May 9, 2025
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Critical
Unreviewed
CVE-2025-28203
was published
May 9, 2025
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management...
Critical
Unreviewed
CVE-2025-46191
was published
May 9, 2025
ProTip!
Advisories are also available from the
GraphQL API