GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
244 advisories
Filter by severity
Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted...
Moderate
Unreviewed
CVE-2006-2056
was published
May 1, 2022
Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers...
Moderate
Unreviewed
CVE-2006-2057
was published
May 1, 2022
Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote...
Moderate
Unreviewed
CVE-2006-2058
was published
May 1, 2022
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote...
Moderate
Unreviewed
CVE-2006-2055
was published
May 1, 2022
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary...
High
Unreviewed
CVE-2006-1865
was published
May 1, 2022
Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify...
Moderate
Unreviewed
CVE-2005-4699
was published
May 1, 2022
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail()...
High
Unreviewed
CVE-2001-1246
was published
Apr 30, 2022
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0,...
High
Unreviewed
CVE-2001-0667
was published
Apr 30, 2022
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are...
Moderate
Unreviewed
CVE-2001-0150
was published
Apr 30, 2022
Some implementations of rlogin allow root access if given a -froot parameter.
High
Unreviewed
CVE-1999-0113
was published
Apr 30, 2022
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier...
High
Unreviewed
CVE-2004-0489
was published
Apr 29, 2022
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters...
Low
Unreviewed
CVE-2004-0473
was published
Apr 29, 2022
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to...
High
Unreviewed
CVE-2004-0480
was published
Apr 29, 2022
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters...
High
Unreviewed
CVE-2004-0411
was published
Apr 29, 2022
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter...
High
Unreviewed
CVE-2004-0121
was published
Apr 29, 2022
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which...
Moderate
Unreviewed
CVE-2003-0907
was published
Apr 29, 2022
Command injection in git-interface
Critical
CVE-2022-1440
was published
for
git-interface
(npm)
Apr 23, 2022
Missing input validation can lead to command execution in composer
High
CVE-2022-24828
was published
for
composer/composer
(Composer)
Apr 22, 2022
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to...
Critical
Unreviewed
CVE-2022-28391
was published
Apr 4, 2022
Command injection in cocoapods-downloader
High
CVE-2022-21223
was published
for
cocoapods-downloader
(RubyGems)
Apr 2, 2022
Command injection in cocoapods-downloader
High
CVE-2022-24440
was published
for
cocoapods-downloader
(RubyGems)
Apr 2, 2022
Command Injection Vulnerability with Mercurial in VCS
Critical
CVE-2022-21235
was published
for
github.com/Masterminds/vcs
(Go)
Apr 1, 2022
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
Critical
Unreviewed
CVE-2021-43736
was published
Mar 24, 2022
ProTip!
Advisories are also available from the
GraphQL API