GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,412
Erlang
28
GitHub Actions
16
Go
1,649
Maven
4,914
npm
3,437
NuGet
594
pip
2,682
Pub
10
RubyGems
822
Rust
760
Swift
34
Unreviewed advisories
All unreviewed
5,000+
1,985 advisories
Filter by severity
A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical....
Moderate
Unreviewed
CVE-2023-1000
was published
Apr 27, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Critical
Unreviewed
CVE-2024-32766
was published
Apr 26, 2024
Runc allows an arbitrary systemd property to be injected
High
CVE-2024-3154
was published
for
github.com/opencontainers/runc
(Go)
Apr 26, 2024
@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE
High
GHSA-qmmm-73r2-f8xr
was published
for
@hoppscotch/cli
(npm)
Apr 22, 2024
Apache HugeGraph-Server: Command execution in gremlin
Critical
CVE-2024-27348
was published
for
org.apache.hugegraph:hugegraph-api
(Maven)
Apr 22, 2024
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart...
Moderate
Unreviewed
CVE-2023-40146
was published
Apr 17, 2024
A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is...
Moderate
Unreviewed
CVE-2024-3908
was published
Apr 17, 2024
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This...
High
Unreviewed
CVE-2024-3871
was published
Apr 16, 2024
llama-index-core Command Injection vulnerability
Critical
CVE-2024-3271
was published
for
llama-index-core
(pip)
Apr 16, 2024
gix-transport indirect code execution via malicious username
Moderate
CVE-2024-32884
was published
for
gitoxide
(Rust)
Apr 15, 2024
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS...
Critical
Unreviewed
CVE-2024-3400
was published
Apr 12, 2024
Microsoft Defender for IoT Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-21322
was published
Apr 9, 2024
A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS...
High
Unreviewed
CVE-2024-3273
was published
Apr 4, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2024-27972
was published
Apr 3, 2024
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat...
Critical
Unreviewed
CVE-2023-41724
was published
Mar 31, 2024
aliyundrive-webdav vulnerable to Command Injection
High
CVE-2024-29640
was published
for
aliyundrive-webdav
(pip)
Mar 29, 2024
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web...
High
Unreviewed
CVE-2024-2947
was published
Mar 28, 2024
A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected...
Moderate
Unreviewed
CVE-2024-3009
was published
Mar 28, 2024
A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-2991
was published
Mar 27, 2024
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub in the...
High
Unreviewed
CVE-2024-29946
was published
Mar 27, 2024
A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected...
Moderate
Unreviewed
CVE-2024-2982
was published
Mar 27, 2024
Gradio's CI vulnerable to Command Injection
High
CVE-2024-1540
was published
for
gradio
(pip)
Mar 27, 2024
•
withdrawn
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-24897
was published
Mar 25, 2024
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as...
High
Unreviewed
CVE-2024-2642
was published
Mar 20, 2024
RCE in TranformGraph().to_dot_graph function
High
CVE-2023-41334
was published
for
astropy
(pip)
Mar 18, 2024
ProTip!
Advisories are also available from the
GraphQL API