GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,152
Maven
5,000+
npm
3,816
NuGet
692
pip
3,492
Pub
12
RubyGems
902
Rust
900
Swift
38
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
LibreNMS has an Authenticated OS Command Injection
Critical
CVE-2024-51092
was published
for
librenms/librenms
(Composer)
Nov 15, 2024
Passbolt Api Remote code execution
High
GHSA-cv5c-2qv5-w2m2
was published
for
passbolt/passbolt_api
(Composer)
May 20, 2024
fuel/core ImageMagick driver does not escape all shell arguments.
High
GHSA-26hp-cgjj-m2j3
was published
for
fuel/core
(Composer)
May 15, 2024
baserCMS OS command injection vulnerability in Installer
Moderate
CVE-2023-51450
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
Magento Open Source allows OS Command Injection
High
CVE-2024-20720
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
Dolibarr allows a remote privileged attacker to execute arbitrary code via a crafted command/script
High
CVE-2023-38886
was published
for
dolibarr/dolibarr
(Composer)
Sep 20, 2023
Magento Open Source allows Improper Neutralization of Special Elements Used
High
CVE-2023-38208
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Dolibarr vulnerable to remote code execution via uppercase manipulation
High
CVE-2023-30253
was published
for
dolibarr/dolibarr
(Composer)
May 29, 2023
Remote code injection in wwbn/avideo
High
CVE-2023-30854
was published
for
wwbn/avideo
(Composer)
Apr 27, 2023
Duplicate Advisory: AVideo contains Command injection when embedding a video link
Critical
GHSA-wj6r-53f5-q789
was published
for
wwbn/avideo
(Composer)
Apr 25, 2023
•
withdrawn
Magento OS Command Injection
Critical
CVE-2021-21018
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento OS command injection via the WebAPI
Critical
CVE-2021-21016
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento OS command injection via the customer attribute save controller
High
CVE-2021-21015
was published
for
magento/community-edition
(Composer)
May 24, 2022
Zen Cart vulnerable to authenticated remote code execution
High
CVE-2021-3291
was published
for
zencart/zencart
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9583
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9582
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9578
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9576
was published
for
magento/community-edition
(Composer)
May 24, 2022
Froxlor arbitrary code execution via the database configuration options
High
CVE-2020-10235
was published
for
froxlor/froxlor
(Composer)
May 24, 2022
php-shellcommand command injection vulnerability
Critical
CVE-2019-10774
was published
for
mikehaertl/php-shellcommand
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8159
was published
for
magento/community-edition
(Composer)
May 24, 2022
LibreNMS arbitrary OS commands execution
Critical
CVE-2018-20434
was published
for
librenms/librenms
(Composer)
May 24, 2022
OS Command Injection in baserCMS
High
CVE-2018-0569
was published
for
baserproject/basercms
(Composer)
May 14, 2022
Codiad Vulnerable to Shell Command Injection
Critical
CVE-2017-11366
was published
for
codiad/codiad
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API