GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,694
Maven
5,000+
npm
4,321
NuGet
761
pip
4,097
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
73 advisories
Filter by severity
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
High
CVE-2025-62703
was published
for
fugue
(pip)
Nov 25, 2025
pgAdmin 4 has command injection vulnerability on Windows systems
Moderate
CVE-2025-12763
was published
for
pgadmin4
(pip)
Nov 13, 2025
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Moderate
CVE-2025-54941
was published
for
apache-airflow
(pip)
Oct 30, 2025
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
Critical
CVE-2023-40267
was published
for
GitPython
(pip)
Aug 11, 2023
motionEye vulnerable to RCE via unsanitized motion config parameter
High
CVE-2025-60787
was published
for
motioneye
(pip)
Nov 3, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
SaltStack Salt Command Injection in netapi ssh client
Critical
CVE-2020-16846
was published
for
salt
(pip)
May 24, 2022
Remote code execution (RCE) in Apache Airflow
High
CVE-2020-11978
was published
for
apache-airflow
(pip)
Jul 27, 2020
mcp-kubernetes-server has an OS Command Injection vulnerability
Critical
CVE-2025-59377
was published
for
mcp-kubernetes-server
(pip)
Sep 15, 2025
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
High
CVE-2025-58180
was published
for
octoprint
(pip)
Sep 9, 2025
TkEasyGUI Vulnerable to OS Command Injection
Critical
CVE-2025-55037
was published
for
TkEasyGUI
(pip)
Sep 5, 2025
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
Calibre Web and Autocaliweb have OS Command Injection vulnerability
Moderate
CVE-2025-7404
was published
for
calibreweb
(pip)
Jul 24, 2025
LLama-Index CLI OS command injection vulnerability
High
CVE-2025-1753
was published
for
llama-index-cli
(pip)
May 28, 2025
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
High
CVE-2025-47782
was published
for
motioneye
(pip)
May 15, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Critical
CVE-2024-9053
was published
for
vllm
(pip)
Mar 20, 2025
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
High
CVE-2024-53305
was published
for
whoogle-search
(pip)
Apr 16, 2025
Duplicate Advisory: D-Tale Command Injection vulnerability
Critical
CVE-2025-0655
was published
for
dtale
(pip)
Mar 20, 2025
•
withdrawn
Improper Control of Generation of Code ('Code Injection') in Azure CLI
High
CVE-2022-39327
was published
for
azure-cli
(pip)
Oct 25, 2022
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
High
CVE-2025-30370
was published
for
jupyterlab-git
(pip)
Apr 4, 2025
pgAdmin failed to properly control the server code
Moderate
CVE-2023-5002
was published
for
pgadmin4
(pip)
Sep 22, 2023
PaddlePaddle command injection in paddle.utils.download._wget_download
High
CVE-2024-0815
was published
for
paddlepaddle
(pip)
Mar 7, 2024
virtualenv allows command injection through activation scripts for a virtual environment
High
CVE-2024-53899
was published
for
virtualenv
(pip)
Nov 24, 2024
ProTip!
Advisories are also available from the
GraphQL API