GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
209 advisories
Filter by severity
Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930
Critical
GHSA-p69r-v3h4-rj4f
was published
for
github.com/gogs/gogs
(Go)
Jul 4, 2024
•
withdrawn
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing...
Unknown
Unreviewed
CVE-2024-35307
was published
Jun 10, 2024
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2023-50232
was published
May 3, 2024
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-44452
was published
May 3, 2024
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit,...
Moderate
Unreviewed
CVE-2024-31966
was published
May 2, 2024
A server side request forgery vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2024-3684
was published
Apr 19, 2024
HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches
Critical
CVE-2024-3817
was published
for
github.com/hashicorp/go-getter
(Go)
Apr 17, 2024
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p25 and <2.3.0b5...
Moderate
Unreviewed
CVE-2024-3367
was published
Apr 16, 2024
gix-transport indirect code execution via malicious username
Moderate
CVE-2024-32884
was published
for
gitoxide
(Rust)
Apr 15, 2024
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not...
Moderate
Unreviewed
CVE-2024-3775
was published
Apr 15, 2024
A remote, unauthenticated attacker may be able to send crafted messages
to the web server of the...
High
Unreviewed
CVE-2024-22182
was published
Mar 1, 2024
Code execution in Embedchain
Critical
CVE-2024-23731
was published
for
embedchain
(pip)
Jan 21, 2024
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved...
Moderate
Unreviewed
CVE-2023-20260
was published
Jan 17, 2024
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual...
Moderate
Unreviewed
CVE-2024-20287
was published
Jan 17, 2024
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments....
High
Unreviewed
CVE-2023-47804
was published
Dec 29, 2023
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2023-46681
was published
Dec 26, 2023
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software...
Moderate
Unreviewed
CVE-2023-6792
was published
Dec 13, 2023
An argument injection vulnerability has been identified in the
administrative web interface of...
Critical
Unreviewed
CVE-2023-6269
was published
Dec 5, 2023
gix-transport code execution vulnerability
Moderate
GHSA-rrjw-j4m2-mf34
was published
for
gix-transport
(Rust)
Sep 25, 2023
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local...
High
Unreviewed
CVE-2023-0633
was published
Sep 25, 2023
blamer vulnerable to Arbitrary Argument Injection via the blameByFile() API
Moderate
CVE-2023-26143
was published
for
blamer
(npm)
Sep 19, 2023
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24...
Moderate
Unreviewed
CVE-2023-39287
was published
Aug 26, 2023
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6...
Moderate
Unreviewed
CVE-2023-39288
was published
Aug 26, 2023
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation...
High
Unreviewed
CVE-2023-20224
was published
Aug 17, 2023
There is a command injection problem in the old version of the mobile phone backup app.
Critical
Unreviewed
CVE-2023-26310
was published
Aug 9, 2023
ProTip!
Advisories are also available from the
GraphQL API