GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,697 advisories
Filter by severity
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
Critical
Unreviewed
CVE-2023-49435
was published
Dec 7, 2023
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49436
was published
Dec 7, 2023
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49428
was published
Dec 7, 2023
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the ...
Critical
Unreviewed
CVE-2023-49437
was published
Dec 7, 2023
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary...
Moderate
Unreviewed
CVE-2023-24046
was published
Dec 5, 2023
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains...
Critical
Unreviewed
CVE-2023-48801
was published
Dec 2, 2023
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via...
Critical
Unreviewed
CVE-2023-48842
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43455
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43454
was published
Dec 1, 2023
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote...
Critical
Unreviewed
CVE-2023-43453
was published
Dec 1, 2023
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to...
High
Unreviewed
CVE-2023-6071
was published
Nov 30, 2023
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2023-49040
was published
Nov 27, 2023
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to...
High
Unreviewed
CVE-2023-49213
was published
Nov 24, 2023
Multiple authenticated command injection vulnerabilities exist in the command line interface....
High
Unreviewed
CVE-2023-45625
was published
Nov 15, 2023
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a...
High
Unreviewed
CVE-2023-42326
was published
Nov 14, 2023
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html...
Critical
Unreviewed
CVE-2023-47253
was published
Nov 6, 2023
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2023-23369
was published
Nov 3, 2023
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center ...
High
Unreviewed
CVE-2023-20219
was published
Nov 1, 2023
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management...
High
Unreviewed
CVE-2023-20220
was published
Nov 1, 2023
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2023-20170
was published
Nov 1, 2023
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-46485
was published
Oct 31, 2023
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-46484
was published
Oct 31, 2023
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no...
Critical
Unreviewed
CVE-2023-46993
was published
Oct 31, 2023
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2023-46979
was published
Oct 31, 2023
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter...
Critical
Unreviewed
CVE-2023-46976
was published
Oct 31, 2023
ProTip!
Advisories are also available from the
GraphQL API