GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,792
Erlang
36
GitHub Actions
29
Go
2,377
Maven
5,000+
npm
4,002
NuGet
720
pip
3,802
Pub
12
RubyGems
927
Rust
984
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
659 advisories
Filter by severity
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when...
Critical
Unreviewed
CVE-2025-26003
was published
Mar 26, 2025
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to...
Critical
Unreviewed
CVE-2024-24525
was published
Feb 29, 2024
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2024-31004
was published
Apr 2, 2024
An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code...
Critical
Unreviewed
CVE-2024-25249
was published
Feb 21, 2024
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the...
Critical
Unreviewed
CVE-2022-48175
was published
Jan 31, 2023
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case...
Critical
Unreviewed
CVE-2025-29306
was published
Mar 27, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RomethemeKit...
Critical
Unreviewed
CVE-2025-30911
was published
Apr 1, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets...
Critical
Unreviewed
CVE-2025-30580
was published
Apr 1, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54803
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54805
was published
Mar 31, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in...
Critical
Unreviewed
CVE-2024-54807
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54804
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi...
Critical
Unreviewed
CVE-2024-54806
was published
Mar 31, 2025
The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all...
Critical
Unreviewed
CVE-2024-13645
was published
Apr 4, 2025
Netwrix Password Secure through 9.2 allows command injection.
Critical
Unreviewed
CVE-2025-26818
was published
Apr 3, 2025
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2025-29064
was published
Apr 3, 2025
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function...
Critical
Unreviewed
CVE-2025-27429
was published
Apr 8, 2025
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a...
Critical
Unreviewed
CVE-2025-31330
was published
Apr 8, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto...
Critical
Unreviewed
CVE-2024-25096
was published
Apr 3, 2024
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS)...
Critical
Unreviewed
CVE-2022-48198
was published
Jan 1, 2023
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP...
Critical
Unreviewed
CVE-2015-5721
was published
May 17, 2022
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly...
Critical
Unreviewed
CVE-2025-1782
was published
Apr 14, 2025
In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open...
Critical
Unreviewed
CVE-2025-3579
was published
Apr 15, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a...
Critical
Unreviewed
CVE-2025-28146
was published
Apr 4, 2025
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded...
Critical
Unreviewed
CVE-2025-3114
was published
Apr 9, 2025
ProTip!
Advisories are also available from the
GraphQL API