GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
784 advisories
Filter by severity
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically...
High
Unreviewed
CVE-2024-4267
was published
May 22, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-1417
was published
May 16, 2024
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5...
High
Unreviewed
CVE-2024-31485
was published
May 14, 2024
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This...
High
Unreviewed
CVE-2024-3871
was published
Apr 16, 2024
Microsoft Defender for IoT Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-21322
was published
Apr 9, 2024
A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS...
High
Unreviewed
CVE-2024-3273
was published
Apr 4, 2024
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web...
High
Unreviewed
CVE-2024-2947
was published
Mar 28, 2024
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub in the...
High
Unreviewed
CVE-2024-29946
was published
Mar 27, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-24897
was published
Mar 25, 2024
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as...
High
Unreviewed
CVE-2024-2642
was published
Mar 20, 2024
Outlook for Android Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-26204
was published
Mar 12, 2024
When running in appliance mode, an authenticated remote command injection vulnerability exists in...
High
Unreviewed
CVE-2024-22093
was published
Feb 14, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-1354
was published
Feb 13, 2024
Azure DevOps Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20667
was published
Feb 13, 2024
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It...
High
Unreviewed
CVE-2023-40263
was published
Feb 9, 2024
An OS command injection vulnerability has been reported to affect Photo Station. If exploited,...
High
Unreviewed
CVE-2023-47562
was published
Feb 2, 2024
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method...
High
Unreviewed
CVE-2024-22107
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22900
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22903
was published
Feb 2, 2024
TRENDnet TEW-824DRU version 1.04b01 is vulnerable to Command Injection via the system.ntp.server...
High
Unreviewed
CVE-2024-22545
was published
Jan 26, 2024
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to...
High
Unreviewed
CVE-2023-51833
was published
Jan 26, 2024
HPE OneView may allow command injection with local privilege escalation.
High
Unreviewed
CVE-2023-50274
was published
Jan 23, 2024
Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection...
High
Unreviewed
CVE-2023-24135
was published
Jan 22, 2024
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters...
High
Unreviewed
CVE-2023-4797
was published
Jan 16, 2024
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and...
High
Unreviewed
CVE-2023-6634
was published
Jan 11, 2024
ProTip!
Advisories are also available from the
GraphQL API