GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,956
Erlang
29
GitHub Actions
16
Go
1,745
Maven
4,969
npm
3,507
NuGet
609
pip
3,066
Pub
10
RubyGems
832
Rust
780
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
730 advisories
Filter by severity
A vulnerability in the PyTorch's torch.distributed.rpc framework, specifically in versions prior...
Critical
Unreviewed
CVE-2024-5480
was published
Jun 6, 2024
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn...
Critical
Unreviewed
CVE-2024-36604
was published
Jun 4, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-34792
was published
Jun 4, 2024
A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows...
Critical
Unreviewed
CVE-2024-4078
was published
May 16, 2024
A remote code execution vulnerability exists in the parisneo/lollms-webui application,...
Critical
Unreviewed
CVE-2024-2366
was published
May 16, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2024-32766
was published
Apr 26, 2024
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS...
Critical
Unreviewed
CVE-2024-3400
was published
Apr 12, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-27972
was published
Apr 3, 2024
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat...
Critical
Unreviewed
CVE-2023-41724
was published
Mar 31, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1372
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1355
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1359
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1369
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1374
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1378
was published
Feb 13, 2024
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with...
Critical
Unreviewed
CVE-2023-46687
was published
Feb 9, 2024
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-24321
was published
Feb 8, 2024
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-23049
was published
Feb 6, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2023-45025
was published
Feb 2, 2024
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can...
Critical
Unreviewed
CVE-2024-23745
was published
Jan 31, 2024
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An...
Critical
Unreviewed
CVE-2024-23624
was published
Jan 26, 2024
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE...
Critical
Unreviewed
CVE-2024-23625
was published
Jan 26, 2024
A command injection vulnerability exists in the ‘SaveSysLogParams’
parameter of the Motorola...
Critical
Unreviewed
CVE-2024-23626
was published
Jan 26, 2024
A command injection vulnerability exists in the
'SaveStaticRouteIPv6Params' parameter of the...
Critical
Unreviewed
CVE-2024-23628
was published
Jan 26, 2024
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the...
Critical
Unreviewed
CVE-2024-23627
was published
Jan 26, 2024
ProTip!
Advisories are also available from the
GraphQL API