GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,274
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,419
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
955 advisories
Filter by severity
ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command
Critical
CVE-2024-5023
was published
for
consoleme
(pip)
May 16, 2024
Command Injection Vulnerability with Mercurial in VCS
Critical
CVE-2022-21235
was published
for
github.com/Masterminds/vcs
(Go)
Apr 1, 2022
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-34792
was published
Jun 4, 2024
A vulnerability in the PyTorch's torch.distributed.rpc framework, specifically in versions prior...
Critical
Unreviewed
CVE-2024-5480
was published
Jun 6, 2024
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn...
Critical
Unreviewed
CVE-2024-36604
was published
Jun 4, 2024
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have...
Critical
Unreviewed
CVE-2022-45063
was published
Nov 10, 2022
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution...
Critical
Unreviewed
CVE-2024-4884
was published
Jun 25, 2024
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in...
Critical
Unreviewed
CVE-2024-4883
was published
Jun 25, 2024
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of...
Critical
Unreviewed
CVE-2024-33344
was published
Apr 26, 2024
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl...
Critical
Unreviewed
CVE-2024-33789
was published
May 3, 2024
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-32353
was published
May 14, 2024
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2024-37642
was published
Jun 14, 2024
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because...
Critical
Unreviewed
CVE-2014-5470
was published
Jun 22, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The...
Critical
Unreviewed
CVE-2022-32262
was published
Jun 15, 2022
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow...
Critical
Unreviewed
CVE-2021-1498
was published
May 24, 2022
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2024-41319
was published
Jul 23, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52040
was published
Jan 24, 2024
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat...
Critical
Unreviewed
CVE-2023-41724
was published
Mar 31, 2024
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code...
Critical
Unreviewed
CVE-2024-39028
was published
Jul 5, 2024
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the...
Critical
Unreviewed
CVE-2024-36783
was published
Jun 3, 2024
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-34204
was published
May 14, 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via...
Critical
Unreviewed
CVE-2024-37385
was published
Jun 7, 2024
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code...
Critical
Unreviewed
CVE-2024-40110
was published
Jul 12, 2024
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the...
Critical
Unreviewed
CVE-2024-38492
was published
Jul 15, 2024
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2024-41316
was published
Jul 22, 2024
ProTip!
Advisories are also available from the
GraphQL API