GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,099 advisories
Filter by severity
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates...
Critical
Unreviewed
CVE-2023-24540
was published
May 11, 2023
Authenticated command injection vulnerability in the command line interface of a network...
High
Unreviewed
CVE-2025-23052
was published
Jan 14, 2025
An unauthenticated remote attacker can perform a command injection in the OCPP Service with...
High
Unreviewed
CVE-2024-25998
was published
Mar 12, 2024
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an...
Moderate
Unreviewed
CVE-2024-52325
was published
Jan 23, 2025
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via...
High
Unreviewed
CVE-2024-57536
was published
Jan 21, 2025
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2024-57583
was published
Jan 16, 2025
A code injection vulnerability exists in the Ambari Alert Definition
feature, allowing...
High
Unreviewed
CVE-2025-23196
was published
Jan 22, 2025
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Critical
Unreviewed
CVE-2024-54794
was published
Jan 21, 2025
Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can...
High
Unreviewed
CVE-2024-3483
was published
May 15, 2024
Multiple bash files were present in the application's private directory.
Bash files can be used...
Low
Unreviewed
CVE-2024-54681
was published
Jan 17, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57228
was published
Jan 10, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57227
was published
Jan 10, 2025
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
High
Unreviewed
CVE-2024-57211
was published
Jan 10, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57226
was published
Jan 10, 2025
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of...
Moderate
Unreviewed
CVE-2022-47028
was published
May 30, 2023
An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink...
Critical
Unreviewed
CVE-2024-39360
was published
Jan 14, 2025
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of...
Critical
Unreviewed
CVE-2024-37186
was published
Jan 14, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
Moderate
Unreviewed
CVE-2024-57222
was published
Jan 10, 2025
An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun()...
Critical
Unreviewed
CVE-2024-39367
was published
Jan 14, 2025
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
Moderate
Unreviewed
CVE-2024-57214
was published
Jan 10, 2025
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
Moderate
Unreviewed
CVE-2024-57212
was published
Jan 10, 2025
An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync()...
Critical
Unreviewed
CVE-2024-34166
was published
Jan 14, 2025
Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg,...
Critical
Unreviewed
CVE-2025-22949
was published
Jan 10, 2025
ProTip!
Advisories are also available from the
GraphQL API