GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,956
Erlang
29
GitHub Actions
16
Go
1,740
Maven
4,967
npm
3,507
NuGet
609
pip
3,064
Pub
10
RubyGems
832
Rust
780
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,703 advisories
Filter by severity
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code...
High
Unreviewed
CVE-2023-38829
was published
Sep 11, 2023
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2...
Critical
Unreviewed
CVE-2023-4310
was published
Sep 5, 2023
SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command...
Critical
Unreviewed
CVE-2023-38027
was published
Aug 28, 2023
There is a command injection vulnerability in a mobile internet product of ZTE. Due to...
High
Unreviewed
CVE-2023-25649
was published
Aug 25, 2023
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-39834
was published
Aug 24, 2023
?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats...
Moderate
Unreviewed
CVE-2023-4212
was published
Aug 22, 2023
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to...
High
Unreviewed
CVE-2023-23564
was published
Aug 22, 2023
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash)...
High
Unreviewed
CVE-2020-22570
was published
Aug 22, 2023
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2023-39618
was published
Aug 21, 2023
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to...
Critical
Unreviewed
CVE-2023-39617
was published
Aug 21, 2023
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2023-39809
was published
Aug 21, 2023
An issue in RG-EW series home routers and repeaters v.EW_3.0(1)B11P204, RG-NBS and RG-S1930...
High
Unreviewed
CVE-2023-38902
was published
Aug 17, 2023
Improper neutralization of special elements used in a command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2023-2910
was published
Aug 17, 2023
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection...
Critical
Unreviewed
CVE-2023-34215
was published
Aug 17, 2023
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and...
Critical
Unreviewed
CVE-2023-34214
was published
Aug 17, 2023
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability...
Critical
Unreviewed
CVE-2023-34213
was published
Aug 17, 2023
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and...
Critical
Unreviewed
CVE-2023-33239
was published
Aug 17, 2023
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and...
Critical
Unreviewed
CVE-2023-33238
was published
Aug 17, 2023
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588....
Critical
Unreviewed
CVE-2023-38866
was published
Aug 15, 2023
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2023-38864
was published
Aug 15, 2023
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0....
Critical
Unreviewed
CVE-2023-38865
was published
Aug 15, 2023
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2023-38862
was published
Aug 15, 2023
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2023-38861
was published
Aug 15, 2023
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname...
Critical
Unreviewed
CVE-2023-38863
was published
Aug 15, 2023
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC...
Moderate
Unreviewed
CVE-2023-40293
was published
Aug 14, 2023
ProTip!
Advisories are also available from the
GraphQL API