GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,958
Erlang
29
GitHub Actions
16
Go
1,745
Maven
4,971
npm
3,507
NuGet
609
pip
3,066
Pub
10
RubyGems
832
Rust
780
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,703 advisories
Filter by severity
There is a command injection vulnerability in some ZTE mobile internet products. Due to...
High
Unreviewed
CVE-2023-25643
was published
Dec 14, 2023
An improper neutralization of special elements used in a command ('Command Injection')...
High
Unreviewed
CVE-2023-48791
was published
Dec 13, 2023
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP...
Moderate
Unreviewed
CVE-2023-4958
was published
Dec 12, 2023
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated...
Moderate
Unreviewed
CVE-2023-49587
was published
Dec 12, 2023
NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.
Critical
Unreviewed
CVE-2023-40301
was published
Dec 7, 2023
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49431
was published
Dec 7, 2023
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49436
was published
Dec 7, 2023
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
Critical
Unreviewed
CVE-2023-49435
was published
Dec 7, 2023
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49437
was published
Dec 7, 2023
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49428
was published
Dec 7, 2023
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary...
Moderate
Unreviewed
CVE-2023-24046
was published
Dec 5, 2023
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains...
Critical
Unreviewed
CVE-2023-48801
was published
Dec 2, 2023
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-48842
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43455
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43454
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43453
was published
Dec 1, 2023
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to...
High
Unreviewed
CVE-2023-6071
was published
Nov 30, 2023
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2023-49040
was published
Nov 27, 2023
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to...
High
Unreviewed
CVE-2023-49213
was published
Nov 24, 2023
Multiple authenticated command injection vulnerabilities exist in the command line interface....
High
Unreviewed
CVE-2023-45625
was published
Nov 15, 2023
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a...
High
Unreviewed
CVE-2023-42326
was published
Nov 14, 2023
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html...
Critical
Unreviewed
CVE-2023-47253
was published
Nov 6, 2023
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2023-23369
was published
Nov 3, 2023
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management...
High
Unreviewed
CVE-2023-20220
was published
Nov 1, 2023
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center ...
High
Unreviewed
CVE-2023-20219
was published
Nov 1, 2023
ProTip!
Advisories are also available from the
GraphQL API