GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
387 advisories
Filter by severity
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via...
Moderate
Unreviewed
CVE-2020-8816
was published
May 24, 2022
Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An...
Moderate
Unreviewed
CVE-2024-48008
was published
Dec 13, 2024
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient...
Moderate
Unreviewed
CVE-2024-22065
was published
Oct 29, 2024
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
Moderate
Unreviewed
CVE-2025-23237
was published
Jan 22, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Moderate
Unreviewed
CVE-2024-57024
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Moderate
Unreviewed
CVE-2024-57025
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Moderate
Unreviewed
CVE-2024-57023
was published
Jan 15, 2025
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a...
Moderate
Unreviewed
CVE-2025-0356
was published
Jan 15, 2025
An improper neutralization of special elements used in an os command ('os command injection') in...
Moderate
Unreviewed
CVE-2024-56497
was published
Jan 14, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
Moderate
Unreviewed
CVE-2024-48890
was published
Jan 14, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
Moderate
Unreviewed
CVE-2024-40587
was published
Jan 14, 2025
A improper neutralization of special elements used in an os command ('os command injection') in...
Moderate
Unreviewed
CVE-2024-26012
was published
Jan 14, 2025
An OS command injection vulnerability in Palo Alto Networks Expedition enables an authenticated...
Moderate
Unreviewed
CVE-2025-0107
was published
Jan 11, 2025
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic...
Moderate
Unreviewed
CVE-2024-47918
was published
Dec 30, 2024
IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a...
Moderate
Unreviewed
CVE-2024-28767
was published
Dec 20, 2024
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or...
Moderate
Unreviewed
CVE-2020-21583
was published
Aug 22, 2023
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS)...
Moderate
Unreviewed
CVE-2024-12686
was published
Dec 18, 2024
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-12358
was published
Dec 9, 2024
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121...
Moderate
Unreviewed
CVE-2024-51228
was published
Nov 27, 2024
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS...
Moderate
Unreviewed
CVE-2024-9474
was published
Nov 18, 2024
The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and...
Moderate
Unreviewed
CVE-2024-10896
was published
Nov 28, 2024
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue...
Moderate
Unreviewed
CVE-2024-9076
was published
Sep 22, 2024
A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices...
Moderate
Unreviewed
CVE-2024-50377
was published
Nov 26, 2024
Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability....
Moderate
Unreviewed
CVE-2024-8359
was published
Nov 23, 2024
Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability....
Moderate
Unreviewed
CVE-2024-8358
was published
Nov 23, 2024
ProTip!
Advisories are also available from the
GraphQL API