GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,746
Maven
5,000+
npm
4,346
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,175 advisories
Filter by severity
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that...
High
Unreviewed
CVE-2024-58294
was published
Dec 12, 2025
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine...
High
Unreviewed
CVE-2024-58287
was published
Dec 12, 2025
dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject...
Critical
Unreviewed
CVE-2024-58286
was published
Dec 12, 2025
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade...
Critical
Unreviewed
CVE-2025-65882
was published
Dec 9, 2025
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute...
High
Unreviewed
CVE-2025-13481
was published
Dec 11, 2025
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23...
High
Unreviewed
CVE-2025-34335
was published
Nov 19, 2025
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are...
High
Unreviewed
CVE-2025-34334
was published
Nov 19, 2025
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function...
Moderate
Unreviewed
CVE-2025-14094
was published
Dec 5, 2025
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990...
Moderate
Unreviewed
CVE-2025-14093
was published
Dec 5, 2025
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if...
High
Unreviewed
CVE-2025-67738
was published
Dec 11, 2025
A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the...
Moderate
Unreviewed
CVE-2025-14092
was published
Dec 5, 2025
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2023-34980
was published
Mar 8, 2024
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local...
High
Unreviewed
CVE-2025-65199
was published
Dec 10, 2025
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
Moderate
CVE-2025-67640
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Dec 10, 2025
Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which...
High
Unreviewed
CVE-2025-12121
was published
Nov 20, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in...
Critical
Unreviewed
CVE-2021-47728
was published
Dec 9, 2025
A improper neutralization of special elements used in an os command ('os command injection') in...
High
Unreviewed
CVE-2025-64153
was published
Dec 9, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2025-53679
was published
Dec 9, 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-53949
was published
Dec 9, 2025
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in...
High
Unreviewed
CVE-2025-66644
was published
Dec 5, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58256
was published
Aug 8, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58255
was published
Aug 8, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58257
was published
Aug 8, 2025
A command injection vulnerability has been reported to affect License Center. If exploited, the...
High
Unreviewed
CVE-2024-48863
was published
Dec 6, 2024
ProTip!
Advisories are also available from the
GraphQL API