GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,106 advisories
Filter by severity
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability...
High
Unreviewed
CVE-2024-57211
was published
Jan 10, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57226
was published
Jan 10, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57227
was published
Jan 10, 2025
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-57228
was published
Jan 10, 2025
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a...
High
Unreviewed
CVE-2024-27980
was published
Jan 9, 2025
Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary...
High
Unreviewed
CVE-2024-51442
was published
Jan 8, 2025
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client...
High
Unreviewed
CVE-2024-54007
was published
Jan 7, 2025
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client...
High
Unreviewed
CVE-2024-54006
was published
Jan 7, 2025
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by...
High
Unreviewed
CVE-2024-13129
was published
Jan 4, 2025
An unintended entry point vulnerability has been identified in certain router models, which may...
High
Unreviewed
CVE-2024-13062
was published
Jan 2, 2025
A command injection is possible through the user interface, allowing arbitrary command execution...
High
Unreviewed
CVE-2020-13712
was published
Dec 21, 2024
In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged...
High
Unreviewed
CVE-2024-12111
was published
Dec 19, 2024
In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary...
High
Unreviewed
CVE-2024-39703
was published
Dec 18, 2024
Databricks JDBC Driver Command Injection vulnerability
High
CVE-2024-49194
was published
for
com.databricks:databricks-jdbc
(Maven)
Dec 17, 2024
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in...
High
Unreviewed
CVE-2024-56086
was published
Dec 16, 2024
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can...
High
Unreviewed
CVE-2024-56084
was published
Dec 16, 2024
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a...
High
Unreviewed
CVE-2024-53290
was published
Dec 11, 2024
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting ...
High
Unreviewed
CVE-2024-55544
was published
Dec 10, 2024
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core...
High
Unreviewed
CVE-2024-53919
was published
Dec 10, 2024
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management...
High
Unreviewed
CVE-2024-51771
was published
Dec 3, 2024
An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote...
High
Unreviewed
CVE-2024-51114
was published
Dec 3, 2024
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker...
High
Unreviewed
CVE-2024-29404
was published
Dec 3, 2024
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for...
High
Unreviewed
CVE-2024-11013
was published
Nov 29, 2024
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor...
High
Unreviewed
CVE-2024-38831
was published
Nov 26, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-11665
was published
Nov 25, 2024
ProTip!
Advisories are also available from the
GraphQL API