GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,362
Erlang
33
GitHub Actions
22
Go
2,134
Maven
5,000+
npm
3,797
NuGet
687
pip
3,473
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,012 advisories
Filter by severity
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC...
High
Unreviewed
CVE-2024-8280
was published
Sep 13, 2024
A privilege escalation vulnerability was discovered in XCC that could allow a valid,...
High
Unreviewed
CVE-2024-8278
was published
Sep 13, 2024
Certain models of D-Link wireless routers do not properly validate user input in the telnet...
High
Unreviewed
CVE-2024-45698
was published
Sep 16, 2024
There is a command injection vulnerability that may allow an attacker to inject malicious input...
High
Unreviewed
CVE-2024-45682
was published
Sep 17, 2024
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI)....
High
Unreviewed
CVE-2024-42503
was published
Sep 17, 2024
Authenticated command injection vulnerability exists in the ArubaOS command line interface....
High
Unreviewed
CVE-2024-42502
was published
Sep 17, 2024
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue....
High
Unreviewed
CVE-2024-8957
was published
Sep 17, 2024
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA...
High
Unreviewed
CVE-2024-43778
was published
Sep 18, 2024
Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an...
High
Unreviewed
CVE-2024-44678
was published
Sep 25, 2024
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-46330
was published
Sep 26, 2024
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-46329
was published
Sep 26, 2024
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2024-46628
was published
Sep 26, 2024
An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2024-33368
was published
Sep 27, 2024
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command...
High
Unreviewed
CVE-2024-46658
was published
Oct 3, 2024
@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plugins using git source
High
GHSA-fm76-w8jw-xf8m
was published
for
@saltcorn/plugins-loader
(npm)
Oct 3, 2024
TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via...
High
Unreviewed
CVE-2024-46486
was published
Oct 4, 2024
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'),...
High
Unreviewed
CVE-2024-9054
was published
Oct 4, 2024
A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The...
High
Unreviewed
CVE-2024-45880
was published
Oct 8, 2024
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2...
High
Unreviewed
CVE-2024-9380
was published
Oct 8, 2024
On Windows platforms, a "best fit" character encoding conversion of command line arguments to...
High
Unreviewed
CVE-2024-45720
was published
Oct 9, 2024
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-46316
was published
Oct 9, 2024
The affected product permits OS command injection through improperly restricted commands,...
High
Unreviewed
CVE-2024-9139
was published
Oct 14, 2024
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone...
High
Unreviewed
CVE-2024-20458
was published
Oct 16, 2024
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command...
High
Unreviewed
CVE-2024-48631
was published
Oct 17, 2024
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command...
High
Unreviewed
CVE-2024-48633
was published
Oct 17, 2024
ProTip!
Advisories are also available from the
GraphQL API