GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,082 advisories
Filter by severity
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor...
High
Unreviewed
CVE-2024-38831
was published
Nov 26, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-11665
was published
Nov 25, 2024
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual...
High
Unreviewed
CVE-2024-53899
was published
Nov 24, 2024
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited,...
High
Unreviewed
CVE-2024-38644
was published
Nov 22, 2024
An OS command injection vulnerability has been reported to affect several product versions. If...
High
Unreviewed
CVE-2024-48861
was published
Nov 22, 2024
Possible Elevation of Privilege Vulnerability
in iManager has been discovered in
OpenText™...
High
Unreviewed
CVE-2021-38116
was published
Nov 22, 2024
Possible Command Injection
in iManager GET parameter has been discovered in
OpenText™ iManager...
High
Unreviewed
CVE-2023-24467
was published
Nov 22, 2024
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
High
Unreviewed
CVE-2024-48286
was published
Nov 21, 2024
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE)...
High
Unreviewed
CVE-2024-52739
was published
Nov 20, 2024
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
High
Unreviewed
CVE-2024-45505
was published
Nov 18, 2024
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
High
CVE-2024-52308
was published
for
github.com/cli/cli
(Go)
Nov 14, 2024
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-50852
was published
Nov 13, 2024
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the...
High
Unreviewed
CVE-2024-50853
was published
Nov 13, 2024
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME...
High
Unreviewed
CVE-2024-28726
was published
Nov 13, 2024
Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the...
High
Unreviewed
CVE-2021-27702
was published
Nov 13, 2024
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49042
was published
Nov 12, 2024
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-43613
was published
Nov 12, 2024
Microsoft Excel Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49026
was published
Nov 12, 2024
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All...
High
Unreviewed
CVE-2024-50572
was published
Nov 12, 2024
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a...
High
Unreviewed
CVE-2024-49560
was published
Nov 12, 2024
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an...
High
Unreviewed
CVE-2024-49557
was published
Nov 12, 2024
D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via...
High
Unreviewed
CVE-2024-51186
was published
Nov 11, 2024
An attacker with local access the to medical office computer can
escalate his Windows user...
High
Unreviewed
CVE-2024-50591
was published
Nov 8, 2024
Symfony vulnerable to command execution hijack on Windows with Process class
High
CVE-2024-51736
was published
for
symfony/process
(Composer)
Nov 6, 2024
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command...
High
Unreviewed
CVE-2024-47461
was published
Nov 6, 2024
ProTip!
Advisories are also available from the
GraphQL API