GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,967
Erlang
29
GitHub Actions
16
Go
1,748
Maven
4,978
npm
3,509
NuGet
609
pip
3,073
Pub
10
RubyGems
832
Rust
781
Swift
34
Unreviewed advisories
All unreviewed
5,000+
140 advisories
Filter by severity
Command Injection in VIVO Vitro
High
CVE-2019-6986
was published
for
org.vivoweb:vitro-project
(Maven)
May 13, 2022
Apache Directory Studio Command Injection
High
CVE-2015-5349
was published
for
org.apache.directory.studio:org.apache.directory.studio.ldapbrowser.core
(Maven)
May 13, 2022
Command injection in czproject/git-php
High
CVE-2022-25866
was published
for
czproject/git-php
(Composer)
Apr 26, 2022
Command injection in libvcs and vcspull
High
CVE-2022-21187
was published
for
libvcs
(pip)
Mar 15, 2022
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
High
CVE-2022-23915
was published
for
Weblate
(pip)
Mar 4, 2022
OS Command Injection and Command Injection in kill-port-process
High
CVE-2019-15609
was published
for
kill-port-process
(npm)
Feb 10, 2022
Pipenv's requirements.txt parsing allows malicious index url in comments
High
CVE-2022-21668
was published
for
pipenv
(pip)
Jan 12, 2022
An authenticated user can execute arbitrary command in Gerapy
High
CVE-2021-32849
was published
for
gerapy
(pip)
Jan 6, 2022
Arbitrary command execution on Windows via qutebrowserurl: URL handler
High
CVE-2021-41146
was published
for
qutebrowser
(pip)
Oct 22, 2021
Improper escaping of command arguments on Windows leading to command injection
High
CVE-2021-41116
was published
for
composer/composer
(Composer)
Oct 5, 2021
Improper Input Validation and Command Injection in Ansible
High
CVE-2021-3583
was published
for
ansible
(pip)
Sep 23, 2021
Remote Code Execution in Apache Dubbo
High
CVE-2021-36162
was published
for
org.apache.dubbo:dubbo
(Maven)
Sep 8, 2021
Command Injection in RaspAP 2.6.6
High
CVE-2021-38556
was published
for
billz/raspap-webgui
(Composer)
Sep 2, 2021
Command injection in mail agent settings
High
CVE-2021-37708
was published
for
shopware/core
(Composer)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API