GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,889 advisories
Filter by severity
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-39471
was published
May 3, 2024
Improper neutralization of special elements used in a command ('command injection') in GitHub...
High
Unreviewed
CVE-2025-53773
was published
Aug 12, 2025
A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows...
Moderate
Unreviewed
CVE-2025-45317
was published
Aug 13, 2025
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center ...
Moderate
Unreviewed
CVE-2025-20306
was published
Aug 14, 2025
The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints...
High
Unreviewed
CVE-2024-53945
was published
Aug 14, 2025
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function...
Moderate
Unreviewed
CVE-2025-9026
was published
Aug 15, 2025
An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing...
Moderate
Unreviewed
CVE-2025-50515
was published
Aug 14, 2025
Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability...
High
Unreviewed
CVE-2023-42128
was published
May 3, 2024
A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22939
was published
Mar 31, 2025
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22941
was published
Mar 31, 2025
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection...
Moderate
Unreviewed
CVE-2025-55590
was published
Aug 18, 2025
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-55591
was published
Aug 18, 2025
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to...
Critical
Unreviewed
CVE-2020-13117
was published
May 24, 2022
screenshot-desktop vulnerable to command Injection via `format` option
Critical
CVE-2025-55294
was published
for
screenshot-desktop
(npm)
Aug 19, 2025
Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie...
Moderate
Unreviewed
CVE-2025-50891
was published
Aug 19, 2025
An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData...
Moderate
Unreviewed
CVE-2025-52337
was published
Aug 19, 2025
A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts...
Moderate
Unreviewed
CVE-2025-50461
was published
Aug 19, 2025
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9174
was published
Aug 20, 2025
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email...
Moderate
Unreviewed
CVE-2025-57733
was published
Aug 20, 2025
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and...
Moderate
Unreviewed
CVE-2025-9244
was published
Aug 20, 2025
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-6269
was published
Jun 23, 2024
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a...
Critical
Unreviewed
CVE-2025-24285
was published
Aug 21, 2025
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a...
High
Unreviewed
CVE-2025-48978
was published
Aug 21, 2025
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API