GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
842 advisories
Filter by severity
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-46457
was published
Feb 9, 2022
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-46453
was published
Feb 9, 2022
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-46452
was published
Feb 9, 2022
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-46455
was published
Feb 9, 2022
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-46454
was published
Feb 9, 2022
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-24168
was published
Feb 9, 2022
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-24167
was published
Feb 9, 2022
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-24171
was published
Feb 9, 2022
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-24170
was published
Feb 9, 2022
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu...
Critical
Unreviewed
CVE-2021-44247
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24144
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24148
was published
Feb 8, 2022
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2022-24150
was published
Feb 8, 2022
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45733
was published
Feb 5, 2022
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2021-45738
was published
Feb 5, 2022
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2021-45742
was published
Feb 5, 2022
A command injection remote code execution vulnerability was discovered on Western Digital My...
Critical
Unreviewed
CVE-2022-22992
was published
Jan 29, 2022
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to...
Critical
Unreviewed
CVE-2021-46560
was published
Jan 27, 2022
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check.
Critical
Unreviewed
CVE-2022-23935
was published
Jan 26, 2022
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Critical
Unreviewed
CVE-2021-44735
was published
Jan 21, 2022
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone...
Critical
Unreviewed
CVE-2021-33963
was published
Jan 16, 2022
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController:...
Critical
Unreviewed
CVE-2021-45807
was published
Jan 14, 2022
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command...
Critical
Unreviewed
CVE-2021-43711
was published
Jan 5, 2022
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated...
Critical
Unreviewed
CVE-2021-45513
was published
Dec 27, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This...
Critical
Unreviewed
CVE-2021-45612
was published
Dec 27, 2021
ProTip!
Advisories are also available from the
GraphQL API