GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,988
Erlang
29
GitHub Actions
16
Go
1,776
Maven
5,000+
npm
3,542
NuGet
617
pip
3,125
Pub
10
RubyGems
838
Rust
790
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,754 advisories
Filter by severity
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2023-41283
was published
Feb 2, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2023-41282
was published
Feb 2, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2023-45025
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22900
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22903
was published
Feb 2, 2024
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by...
Low
Unreviewed
CVE-2024-0325
was published
Feb 2, 2024
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can...
Critical
Unreviewed
CVE-2024-23745
was published
Jan 31, 2024
A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2024-0920
was published
Jan 26, 2024
TRENDnet TEW-824DRU version 1.04b01 is vulnerable to Command Injection via the system.ntp.server...
High
Unreviewed
CVE-2024-22545
was published
Jan 26, 2024
A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical....
Moderate
Unreviewed
CVE-2024-0919
was published
Jan 26, 2024
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An...
Critical
Unreviewed
CVE-2024-23624
was published
Jan 26, 2024
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE...
Critical
Unreviewed
CVE-2024-23625
was published
Jan 26, 2024
A command injection vulnerability exists in the ‘SaveSysLogParams’
parameter of the Motorola...
Critical
Unreviewed
CVE-2024-23626
was published
Jan 26, 2024
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the...
Critical
Unreviewed
CVE-2024-23627
was published
Jan 26, 2024
A command injection vulnerability exists in the
'SaveStaticRouteIPv6Params' parameter of the...
Critical
Unreviewed
CVE-2024-23628
was published
Jan 26, 2024
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to...
High
Unreviewed
CVE-2023-51833
was published
Jan 26, 2024
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command...
Critical
Unreviewed
CVE-2023-7227
was published
Jan 25, 2024
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040...
Critical
Unreviewed
CVE-2024-22529
was published
Jan 25, 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2024-22729
was published
Jan 25, 2024
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute...
Critical
Unreviewed
CVE-2023-51887
was published
Jan 24, 2024
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D...
Critical
Unreviewed
CVE-2024-22651
was published
Jan 24, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52038
was published
Jan 24, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52040
was published
Jan 24, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52039
was published
Jan 24, 2024
HPE OneView may allow command injection with local privilege escalation.
High
Unreviewed
CVE-2023-50274
was published
Jan 23, 2024
ProTip!
Advisories are also available from the
GraphQL API