GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,055 advisories
Filter by severity
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor...
Critical
Unreviewed
CVE-2025-10035
was published
Sep 19, 2025
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2025-52053
was published
Sep 15, 2025
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application....
Critical
Unreviewed
CVE-2025-10364
was published
Sep 12, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated...
Critical
Unreviewed
CVE-2025-57633
was published
Sep 9, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the...
Critical
Unreviewed
CVE-2025-50428
was published
Aug 27, 2025
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2025-50722
was published
Aug 26, 2025
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute...
Critical
Unreviewed
CVE-2025-57105
was published
Aug 22, 2025
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a...
Critical
Unreviewed
CVE-2025-24285
was published
Aug 21, 2025
screenshot-desktop vulnerable to command Injection via `format` option
Critical
CVE-2025-55294
was published
for
screenshot-desktop
(npm)
Aug 19, 2025
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-55591
was published
Aug 18, 2025
Active Storage allowed transformation methods that were potentially unsafe
Critical
CVE-2025-24293
was published
for
activestorage
(RubyGems)
Aug 14, 2025
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers
Critical
CVE-2025-54782
was published
for
@nestjs/devtools-integration
(npm)
Aug 1, 2025
An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to...
Critical
Unreviewed
CVE-2025-26063
was published
Jul 31, 2025
tj-actions/branch-names has a Command Injection Vulnerability
Critical
CVE-2025-54416
was published
for
tj-actions/branch-names
(GitHub Actions)
Jul 25, 2025
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2025-52046
was published
Jul 17, 2025
Successful exploitation of the vulnerability could allow an attacker to inject commands with root...
Critical
Unreviewed
CVE-2025-52688
was published
Jul 16, 2025
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows...
Critical
Unreviewed
CVE-2025-3621
was published
Jul 15, 2025
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2025-50756
was published
Jul 14, 2025
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to...
Critical
Unreviewed
CVE-2025-45931
was published
Jun 30, 2025
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL...
Critical
Unreviewed
CVE-2025-45988
was published
Jun 13, 2025
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL...
Critical
Unreviewed
CVE-2025-45987
was published
Jun 13, 2025
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL...
Critical
Unreviewed
CVE-2025-45986
was published
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API