GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
550 advisories
Filter by severity
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2025-8651
was published
Aug 6, 2025
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2025-8652
was published
Aug 6, 2025
Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2025-8655
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8648
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8643
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8645
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8646
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8633
was published
Aug 6, 2025
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8637
was published
Aug 6, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30097
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30098
was published
Aug 4, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-30096
was published
Aug 4, 2025
Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8473
was published
Aug 1, 2025
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the...
Moderate
Unreviewed
CVE-2025-8259
was published
Jul 28, 2025
gix-transport code execution vulnerability
Moderate
CVE-2023-53158
was published
for
gix-transport
(Rust)
Sep 25, 2023
Duplicate Advisory: gix-transport code execution vulnerability
Moderate
GHSA-5c5j-jmhx-q2gr
was published
for
gix-transport
(Rust)
Jul 28, 2025
•
withdrawn
Calibre Web and Autocaliweb have OS Command Injection vulnerability
Moderate
CVE-2025-7404
was published
for
calibreweb
(pip)
Jul 24, 2025
A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This...
Moderate
Unreviewed
CVE-2025-7553
was published
Jul 14, 2025
A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44....
Moderate
Unreviewed
CVE-2025-1819
was published
Mar 2, 2025
Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated...
Moderate
Unreviewed
CVE-2025-52379
was published
Jul 15, 2025
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version...
Moderate
Unreviewed
CVE-2025-52089
was published
Jul 11, 2025
phpThumb is vulnerable to Command Injection through its gif_outputAsJpeg function
Moderate
CVE-2025-52994
was published
for
james-heinrich/phpthumb
(Composer)
Jul 11, 2025
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that...
Moderate
Unreviewed
CVE-2025-20319
was published
Jul 7, 2025
A physical attacker with no privileges can gain full control of the affected device due to...
Moderate
Unreviewed
CVE-2025-3705
was published
Jul 7, 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell...
Moderate
Unreviewed
CVE-2025-47228
was published
Jul 5, 2025
ProTip!
Advisories are also available from the
GraphQL API