GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
3,334 advisories
Filter by severity
Loomio version 2.22.0 allows executing arbitrary commands on the server.
This is possible...
Critical
Unreviewed
CVE-2024-1297
was published
Feb 20, 2024
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows...
Critical
Unreviewed
CVE-2024-12828
was published
Dec 30, 2024
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to...
High
Unreviewed
CVE-2024-54181
was published
Dec 30, 2024
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS...
Critical
Unreviewed
CVE-2024-47919
was published
Dec 30, 2024
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic...
Moderate
Unreviewed
CVE-2024-47918
was published
Dec 30, 2024
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command...
High
Unreviewed
CVE-2024-12856
was published
Dec 27, 2024
A command injection is possible through the user interface, allowing arbitrary command execution...
High
Unreviewed
CVE-2020-13712
was published
Dec 21, 2024
GoCast OS Command Injection vulnerability
Critical
CVE-2024-28892
was published
for
github.com/mayuresh82/gocast
(Go)
Dec 20, 2024
home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the...
High
Unreviewed
CVE-2024-54082
was published
Dec 23, 2024
home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection...
High
Unreviewed
CVE-2024-45721
was published
Dec 23, 2024
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache...
Critical
Unreviewed
CVE-2024-4577
was published
Jun 9, 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0...
Critical
Unreviewed
CVE-2024-45519
was published
Oct 3, 2024
IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a...
Moderate
Unreviewed
CVE-2024-28767
was published
Dec 20, 2024
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or...
Moderate
Unreviewed
CVE-2020-21583
was published
Aug 22, 2023
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-12829
was published
Dec 20, 2024
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line...
High
Unreviewed
CVE-2021-26115
was published
Dec 19, 2024
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell...
Critical
Unreviewed
CVE-2018-14933
was published
May 13, 2022
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an...
High
Unreviewed
CVE-2019-11001
was published
May 14, 2022
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS)...
Moderate
Unreviewed
CVE-2024-12686
was published
Dec 18, 2024
rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set...
Critical
Unreviewed
CVE-2024-31668
was published
Dec 18, 2024
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2024-48889
was published
Dec 18, 2024
An OS command injection vulnerability exists in the web interface configuration upload...
High
Unreviewed
CVE-2024-21786
was published
Dec 18, 2024
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
High
Unreviewed
CVE-2024-53688
was published
Dec 18, 2024
An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially...
Critical
Unreviewed
CVE-2024-29224
was published
Dec 18, 2024
ProTip!
Advisories are also available from the
GraphQL API