GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,005 advisories
Filter by severity
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially...
High
Unreviewed
CVE-2023-6321
was published
May 15, 2024
An improper neutralization of special elements used in an os command ('os command injection') in...
High
Unreviewed
CVE-2024-50567
was published
Feb 11, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2024-40584
was published
Feb 11, 2025
On Windows platforms, a "best fit" character encoding conversion of command line arguments to...
High
Unreviewed
CVE-2024-45720
was published
Oct 9, 2024
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS...
High
Unreviewed
CVE-2024-8684
was published
Feb 10, 2025
An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to...
High
Unreviewed
CVE-2024-57357
was published
Feb 8, 2025
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate...
High
Unreviewed
CVE-2020-0646
was published
May 24, 2022
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre...
High
Unreviewed
CVE-2020-9054
was published
May 24, 2022
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote...
High
Unreviewed
CVE-2020-4428
was published
May 24, 2022
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command...
High
Unreviewed
CVE-2025-20029
was published
Feb 5, 2025
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers...
High
Unreviewed
CVE-2020-10987
was published
May 24, 2022
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to...
High
Unreviewed
CVE-2019-15949
was published
May 24, 2022
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command...
High
Unreviewed
CVE-2019-16057
was published
May 24, 2022
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the...
High
Unreviewed
CVE-2019-19356
was published
May 24, 2022
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the...
High
Unreviewed
CVE-2018-9276
was published
May 13, 2022
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector...
High
Unreviewed
CVE-2020-4006
was published
May 24, 2022
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A...
High
Unreviewed
CVE-2024-22461
was published
Dec 13, 2024
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability...
High
Unreviewed
CVE-2024-23690
was published
Feb 4, 2025
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the...
High
Unreviewed
CVE-2024-40891
was published
Feb 4, 2025
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI...
High
Unreviewed
CVE-2024-40890
was published
Feb 4, 2025
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service...
High
Unreviewed
CVE-2021-27102
was published
May 24, 2022
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is...
High
Unreviewed
CVE-2024-2662
was published
May 14, 2024
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an...
High
Unreviewed
CVE-2021-38163
was published
May 24, 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17,...
High
Unreviewed
CVE-2022-36804
was published
Aug 26, 2022
ProTip!
Advisories are also available from the
GraphQL API