GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,070
Erlang
29
GitHub Actions
19
Go
1,891
Maven
5,000+
npm
3,628
NuGet
638
pip
3,240
Pub
10
RubyGems
858
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
906 advisories
Filter by severity
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the...
Critical
Unreviewed
CVE-2023-49959
was published
Feb 26, 2024
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2024-25850
was published
Feb 22, 2024
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04...
Critical
Unreviewed
CVE-2023-24331
was published
Feb 21, 2024
pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
Critical
CVE-2024-23346
was published
for
pymatgen
(pip)
Feb 21, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1374
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1378
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1355
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1372
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1369
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1359
was published
Feb 13, 2024
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with...
Critical
Unreviewed
CVE-2023-46687
was published
Feb 9, 2024
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-24321
was published
Feb 8, 2024
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2024-24216
was published
Feb 8, 2024
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-23049
was published
Feb 6, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2023-45025
was published
Feb 2, 2024
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can...
Critical
Unreviewed
CVE-2024-23745
was published
Jan 31, 2024
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE...
Critical
Unreviewed
CVE-2024-23625
was published
Jan 26, 2024
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An...
Critical
Unreviewed
CVE-2024-23624
was published
Jan 26, 2024
A command injection vulnerability exists in the ‘SaveSysLogParams’
parameter of the Motorola...
Critical
Unreviewed
CVE-2024-23626
was published
Jan 26, 2024
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the...
Critical
Unreviewed
CVE-2024-23627
was published
Jan 26, 2024
A command injection vulnerability exists in the
'SaveStaticRouteIPv6Params' parameter of the...
Critical
Unreviewed
CVE-2024-23628
was published
Jan 26, 2024
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command...
Critical
Unreviewed
CVE-2023-7227
was published
Jan 25, 2024
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040...
Critical
Unreviewed
CVE-2024-22529
was published
Jan 25, 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2024-22729
was published
Jan 25, 2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary...
Critical
Unreviewed
CVE-2023-52040
was published
Jan 24, 2024
ProTip!
Advisories are also available from the
GraphQL API