GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            4,087 advisories
        Filter by severity
        
      
      
    
                    
                      IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34312
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34311
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      Command injection vulnerability exists in the “Logging” page of the web-based configuration...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-1036
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      The “Diagnostics Tools” page of the web-based configuration utility does not properly validate...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-1038
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12296
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60803
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10680
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Diagnostics command injection vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6978
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Kottster app reinitialization can be re-triggered allowing command injection in development mode
                    
                      
  High
                    
                
                      
                        CVE-2025-62713
                      
                      was published
                        for
                        
                          @kottster/server
                        
                        (npm)
                      Oct 23, 2025 
                    
                  
                    
                      AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-15048
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-58274
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54469
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8078
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      An arbitrary OS command may be executed on the product by the user who can log in to the web...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6541
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6542
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      A command injection vulnerability may be exploited after the admin's authentication on the web...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-7850
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-25118
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47900
                      
                      was published
                      Oct 20, 2025 
                    
                  
                    
                      Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47901
                      
                      was published
                      Oct 20, 2025 
                    
                  
                    
                      The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11900
                      
                      was published
                      Oct 17, 2025 
                    
                  
                    
                      Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34513
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34514
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
                    
                      
  High
                    
                
                      
                        CVE-2025-59419
                      
                      was published
                        for
                        
                          io.netty:netty-codec-smtp
                        
                        (Maven)
                      Oct 15, 2025 
                    
                  
                    
                      When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53868
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      When a user attempts to initialize the rSeries FIPS module using a password with special shell...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60013
                      
                      was published
                      Oct 15, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API