GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
781 advisories
Filter by severity
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain...
Critical
Unreviewed
CVE-2021-27602
was published
May 24, 2022
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required...
Critical
Unreviewed
CVE-2021-21477
was published
May 24, 2022
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the...
Critical
Unreviewed
CVE-2021-26753
was published
May 24, 2022
FurqanSoftware/node-whois vulnerable to Prototype Pollution
Critical
CVE-2020-36618
was published
for
whois
(npm)
Dec 19, 2022
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php)...
Critical
Unreviewed
CVE-2021-24376
was published
May 24, 2022
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by...
Critical
Unreviewed
CVE-2019-25022
was published
May 24, 2022
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow...
Critical
Unreviewed
CVE-2021-25003
was published
Mar 15, 2022
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
Critical
Unreviewed
CVE-2021-33911
was published
May 24, 2022
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows...
Critical
Unreviewed
CVE-2020-18172
was published
May 24, 2022
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to...
Critical
Unreviewed
CVE-2021-39426
was published
Dec 15, 2022
vm2 vulnerable to Arbitrary Code Execution
Critical
CVE-2022-25893
was published
for
vm2
(npm)
Dec 21, 2022
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php...
Critical
Unreviewed
CVE-2021-36800
was published
May 24, 2022
Code injection in quarkus dev ui config editor
Critical
CVE-2022-4116
was published
for
io.quarkus:quarkus-vertx-http-deployment
(Maven)
Nov 22, 2022
EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application...
Critical
Unreviewed
CVE-2022-30083
was published
Jul 31, 2022
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters,...
Critical
Unreviewed
CVE-2021-32829
was published
May 24, 2022
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to...
Critical
Unreviewed
CVE-2021-29772
was published
May 24, 2022
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs...
Critical
Unreviewed
CVE-2021-40373
was published
May 24, 2022
Deno before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
Critical
Unreviewed
CVE-2021-42139
was published
May 24, 2022
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in ...
Critical
Unreviewed
CVE-2021-40889
was published
May 24, 2022
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application...
Critical
Unreviewed
CVE-2021-40499
was published
May 24, 2022
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that...
Critical
Unreviewed
CVE-2021-22961
was published
May 24, 2022
Apache Cassandra vulnerable to Code Injection due to unsafe configuration
Critical
CVE-2021-44521
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 12, 2022
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter,...
Critical
Unreviewed
CVE-2020-23037
was published
May 24, 2022
RCE vulnerability in Pimcore/Mail & Dynamic Text Layout
Critical
CVE-2022-39365
was published
for
pimcore/pimcore
(Composer)
Oct 29, 2022
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU...
Critical
Unreviewed
CVE-2021-41653
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API