GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,749
Maven
4,978
npm
3,509
NuGet
609
pip
3,084
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
931 advisories
Filter by severity
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as...
High
Unreviewed
CVE-2024-2642
was published
Mar 20, 2024
RCE in TranformGraph().to_dot_graph function
High
CVE-2023-41334
was published
for
astropy
(pip)
Mar 18, 2024
Outlook for Android Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-26204
was published
Mar 12, 2024
When running in appliance mode, an authenticated remote command injection vulnerability exists in...
High
Unreviewed
CVE-2024-22093
was published
Feb 14, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-1354
was published
Feb 13, 2024
Azure DevOps Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20667
was published
Feb 13, 2024
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It...
High
Unreviewed
CVE-2023-40263
was published
Feb 9, 2024
An OS command injection vulnerability has been reported to affect Photo Station. If exploited,...
High
Unreviewed
CVE-2023-47562
was published
Feb 2, 2024
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method...
High
Unreviewed
CVE-2024-22107
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22903
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22900
was published
Feb 2, 2024
network Arbitrary Command Injection vulnerability
High
CVE-2024-21488
was published
for
network
(npm)
Jan 30, 2024
TRENDnet TEW-824DRU version 1.04b01 is vulnerable to Command Injection via the system.ntp.server...
High
Unreviewed
CVE-2024-22545
was published
Jan 26, 2024
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to...
High
Unreviewed
CVE-2023-51833
was published
Jan 26, 2024
HPE OneView may allow command injection with local privilege escalation.
High
Unreviewed
CVE-2023-50274
was published
Jan 23, 2024
Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection...
High
Unreviewed
CVE-2023-24135
was published
Jan 22, 2024
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters...
High
Unreviewed
CVE-2023-4797
was published
Jan 16, 2024
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
High
CVE-2024-22198
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 11, 2024
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
High
CVE-2024-22197
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 11, 2024
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and...
High
Unreviewed
CVE-2023-6634
was published
Jan 11, 2024
Azure Storage Mover Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20676
was published
Jan 9, 2024
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the...
High
Unreviewed
CVE-2023-47560
was published
Jan 5, 2024
Potential Actions command injection in output filenames (GHSL-2023-275)
High
CVE-2023-52137
was published
for
tj-actions/verify-changed-files
(GitHub Actions)
Jan 2, 2024
tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)
High
CVE-2023-51664
was published
for
tj-actions/changed-files
(GitHub Actions)
Jan 2, 2024
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute...
High
Unreviewed
CVE-2023-49226
was published
Dec 25, 2023
ProTip!
Advisories are also available from the
GraphQL API