GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
551 advisories
Filter by severity
Unspecified vulnerability in Sun Solaris 8 directory functions allows local users to cause a...
Moderate
Unreviewed
CVE-2008-1115
was published
May 1, 2022
Untrusted search path vulnerability in GTK2 in OpenSUSE 11.0 and 11.1 allows local users to...
Moderate
Unreviewed
CVE-2009-0848
was published
May 2, 2022
OS Command Injection in export.php (vulnerable function called from include/functions-article.php...
Moderate
Unreviewed
CVE-2020-10390
was published
May 24, 2022
Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users...
Moderate
Unreviewed
CVE-2009-0854
was published
May 2, 2022
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute...
Moderate
Unreviewed
CVE-2009-4498
was published
May 2, 2022
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission...
Moderate
Unreviewed
CVE-2021-30361
was published
May 12, 2022
An exploitable code execution vulnerability exists in the firmware update functionality of Yi...
Moderate
Unreviewed
CVE-2018-3890
was published
May 13, 2022
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an...
Moderate
Unreviewed
CVE-2019-3913
was published
May 13, 2022
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS...
Moderate
Unreviewed
CVE-2019-1725
was published
May 13, 2022
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Moderate
Unreviewed
CVE-2018-0324
was published
May 13, 2022
Command Injection in systeminformation
Moderate
CVE-2020-26300
was published
for
systeminformation
(npm)
Oct 27, 2020
XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
Moderate
CVE-2020-26259
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Dec 21, 2020
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an...
Moderate
Unreviewed
CVE-2018-0214
was published
May 13, 2022
[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values
Moderate
CVE-2021-21412
was published
for
@thi.ng/egf
(npm)
Apr 6, 2021
Arbitrary Command Injection in portprocesses
Moderate
CVE-2021-23348
was published
for
portprocesses
(npm)
Apr 6, 2021
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series...
Moderate
Unreviewed
CVE-2018-0122
was published
May 13, 2022
OS Command injection in Bolt
Moderate
CVE-2020-28925
was published
for
bolt/bolt
(Composer)
May 6, 2021
OS Command Injection in mversion
Moderate
CVE-2020-7688
was published
for
mversion
(npm)
May 17, 2021
OS Command Injection in ng-packagr
Moderate
CVE-2020-7735
was published
for
ng-packagr
(npm)
May 7, 2021
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3,...
Moderate
Unreviewed
CVE-2018-1242
was published
May 13, 2022
OS Command injection in docker-cli-js
Moderate
CVE-2021-23732
was published
for
docker-cli-js
(npm)
Dec 2, 2021
•
withdrawn
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and...
Moderate
Unreviewed
CVE-2021-20853
was published
Dec 2, 2021
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and...
Moderate
Unreviewed
CVE-2021-20854
was published
Dec 2, 2021
ProTip!
Advisories are also available from the
GraphQL API