GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
365 advisories
Filter by severity
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-ccj3-5p93-8p42
was published
for
surrealdb
(Rust)
Apr 11, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels
Moderate
CVE-2025-25274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Duplicate Advisory: D-Tale Command Injection vulnerability
Critical
CVE-2025-0655
was published
for
dtale
(pip)
Mar 20, 2025
•
withdrawn
LiteLLM Vulnerable to Remote Code Execution (RCE)
High
CVE-2024-6825
was published
for
litellm
(pip)
Mar 20, 2025
Horovod Vulnerable to Command Injection
Critical
CVE-2024-10190
was published
for
horovod
(pip)
Mar 20, 2025
Withdrawn Advisory: Dask Vulnerable to Command Injection
Critical
CVE-2024-10096
was published
for
dask
(pip)
Mar 20, 2025
•
withdrawn
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
XPixelGroup BasicSR Command Injection
Moderate
CVE-2024-27763
was published
for
basicsr
(pip)
Mar 12, 2025
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
DocsGPT Allows Remote Code Execution
Critical
CVE-2025-0868
was published
for
docsgpt
(npm)
Feb 20, 2025
files.photo.gallery command injection
Moderate
CVE-2024-53615
was published
for
files.photo.gallery
(npm)
Jan 30, 2025
Composio Command Execution vulnerability
Moderate
CVE-2024-53526
was published
for
composio-claude
(pip)
Jan 8, 2025
Databricks JDBC Driver Command Injection vulnerability
High
CVE-2024-49194
was published
for
com.databricks:databricks-jdbc
(Maven)
Dec 17, 2024
virtualenv allows command injection through activation scripts for a virtual environment
High
CVE-2024-53899
was published
for
virtualenv
(pip)
Nov 24, 2024
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
High
CVE-2024-52308
was published
for
github.com/cli/cli
(Go)
Nov 14, 2024
Symfony vulnerable to command execution hijack on Windows with Process class
High
CVE-2024-51736
was published
for
symfony/process
(Composer)
Nov 6, 2024
Grafana Command Injection And Local File Inclusion Via Sql Expressions
Critical
CVE-2024-9264
was published
for
github.com/grafana/grafana
(Go)
Oct 18, 2024
DeepSpeed Remote Code Execution Vulnerability
High
CVE-2024-43497
was published
for
deepspeed
(pip)
Oct 8, 2024
Command Injection in sequenceserver
Critical
CVE-2024-42360
was published
for
sequenceserver
(RubyGems)
Aug 13, 2024
CasaOS Command Injection vulnerability
Critical
CVE-2023-37469
was published
for
github.com/IceWhaleTech/CasaOS
(Go)
Aug 5, 2024
RaspAP allows an attacker to escalate privileges
Critical
CVE-2024-41637
was published
for
billz/raspap-webgui
(Composer)
Jul 29, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
High
CVE-2024-41815
was published
for
starship
(Rust)
Jul 26, 2024
Apache StreamPark: Unchecked maven build params could trigger remote command execution
Moderate
CVE-2023-52291
was published
for
org.apache.streampark:streampark
(Maven)
Jul 17, 2024
ProTip!
Advisories are also available from the
GraphQL API