GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,447 advisories
Filter by severity
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue...
High
Unreviewed
CVE-2025-26856
was published
Feb 20, 2025
An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an...
Critical
Unreviewed
CVE-2025-1265
was published
Feb 20, 2025
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-28495
was published
Mar 24, 2023
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210...
Moderate
Unreviewed
CVE-2025-1546
was published
Feb 21, 2025
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325...
High
Unreviewed
CVE-2019-1652
was published
May 13, 2022
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE)...
Critical
Unreviewed
CVE-2025-27364
was published
Feb 24, 2025
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco...
Moderate
Unreviewed
CVE-2025-20161
was published
Feb 26, 2025
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers...
Critical
Unreviewed
CVE-2023-28617
was published
Mar 19, 2023
A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU...
Moderate
Unreviewed
CVE-2025-1616
was published
Feb 24, 2025
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate...
Critical
Unreviewed
CVE-2023-25279
was published
Mar 13, 2023
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to...
Critical
Unreviewed
CVE-2023-24762
was published
Mar 13, 2023
A flaw was found in the Emacs text editor. Improper handling of custom "man" URI schemes allows...
High
Unreviewed
CVE-2025-1244
was published
Feb 12, 2025
Magento Open Source allows Improper Neutralization of Special Elements Used
High
CVE-2023-38208
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows OS Command Injection
High
CVE-2024-20720
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS...
High
Unreviewed
CVE-2024-39351
was published
Mar 4, 2025
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS...
High
Unreviewed
CVE-2023-47802
was published
Mar 4, 2025
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted...
Critical
Unreviewed
CVE-2025-1316
was published
Mar 5, 2025
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections...
Critical
Unreviewed
CVE-2023-27985
was published
Mar 9, 2023
t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via...
Moderate
Unreviewed
CVE-2025-26320
was published
Mar 4, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2024-53692
was published
Mar 7, 2025
A command injection vulnerability has been reported to affect QHora. If exploited, the...
High
Unreviewed
CVE-2024-50390
was published
Mar 7, 2025
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891,...
High
Unreviewed
CVE-2023-26213
was published
Mar 4, 2023
ProTip!
Advisories are also available from the
GraphQL API