GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
955 advisories
Filter by severity
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2024-41318
was published
Jul 22, 2024
RaspAP allows an attacker to escalate privileges
Critical
CVE-2024-41637
was published
for
billz/raspap-webgui
(Composer)
Jul 29, 2024
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware...
Critical
Unreviewed
CVE-2024-28354
was published
Mar 15, 2024
Improper filering of special characters result in a command ('command injection') vulnerability...
Critical
Unreviewed
CVE-2024-7397
was published
Aug 5, 2024
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main...
Critical
Unreviewed
CVE-2024-33112
was published
May 6, 2024
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter...
Critical
Unreviewed
CVE-2024-28545
was published
Mar 26, 2024
Multiple OS command injection vulnerabilities affecting Vonets
industrial wifi bridge relays...
Critical
Unreviewed
CVE-2024-37023
was published
Aug 12, 2024
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a...
Critical
Unreviewed
CVE-2024-28739
was published
Aug 6, 2024
Command Injection in sequenceserver
Critical
CVE-2024-42360
was published
for
sequenceserver
(RubyGems)
Aug 13, 2024
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2024-25850
was published
Feb 22, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-21878
was published
Aug 12, 2024
DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the...
Critical
Unreviewed
CVE-2024-29385
was published
Mar 22, 2024
Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution...
Critical
Unreviewed
CVE-2024-42905
was published
Aug 28, 2024
FitNesse allows execution of arbitrary OS commands
Critical
CVE-2024-28125
was published
for
org.fitnesse:fitnesse
(Maven)
Mar 18, 2024
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04...
Critical
Unreviewed
CVE-2023-24331
was published
Feb 21, 2024
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the...
Critical
Unreviewed
CVE-2023-49959
was published
Feb 26, 2024
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows...
Critical
Unreviewed
CVE-2023-52042
was published
Jan 17, 2024
Ansible fails to properly sanitize fact variables sent from the Ansible controller
Critical
CVE-2016-8628
was published
for
ansible
(pip)
Oct 10, 2018
Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into...
Critical
Unreviewed
CVE-2024-29864
was published
Mar 21, 2024
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2024-24216
was published
Feb 8, 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html...
Critical
Unreviewed
CVE-2023-47253
was published
Nov 6, 2023
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows...
Critical
Unreviewed
CVE-2024-42947
was published
Aug 15, 2024
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-46485
was published
Oct 31, 2023
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-46484
was published
Oct 31, 2023
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
Critical
Unreviewed
CVE-2024-44402
was published
Sep 6, 2024
ProTip!
Advisories are also available from the
GraphQL API