GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,272 advisories
Filter by severity
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command...
High
Unreviewed
CVE-2025-54763
was published
Oct 31, 2025
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP...
High
Unreviewed
CVE-2025-34280
was published
Oct 31, 2025
Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF...
High
Unreviewed
CVE-2020-36867
was published
Oct 31, 2025
Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto...
High
Unreviewed
CVE-2013-10073
was published
Oct 31, 2025
Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component...
High
Unreviewed
CVE-2018-25122
was published
Oct 31, 2025
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-43941
was published
Oct 30, 2025
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-43940
was published
Oct 30, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-43942
was published
Oct 30, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-46422
was published
Oct 30, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-43939
was published
Oct 30, 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-46423
was published
Oct 30, 2025
Jenkins Azure CLI Plugin does not restrict the commands it executes
High
CVE-2025-64140
was published
for
org.jenkins-ci.plugins:azure-cli
(Maven)
Oct 29, 2025
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b...
High
Unreviewed
CVE-2025-57516
was published
Sep 29, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-47901
was published
Oct 20, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-47900
was published
Oct 20, 2025
The “Diagnostics Tools” page of the web-based configuration utility does not properly validate...
High
Unreviewed
CVE-2025-1038
was published
Oct 28, 2025
Command injection vulnerability exists in the “Logging” page of the web-based configuration...
High
Unreviewed
CVE-2025-1036
was published
Oct 28, 2025
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that...
High
Unreviewed
CVE-2025-34312
was published
Oct 28, 2025
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that...
High
Unreviewed
CVE-2025-34311
was published
Oct 28, 2025
An arbitrary OS command may be executed on the product by the user who can log in to the web...
High
Unreviewed
CVE-2025-6541
was published
Oct 21, 2025
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated...
High
Unreviewed
CVE-2025-10680
was published
Oct 24, 2025
Command injection vulnerability in the Edge Computing UI for the
TRO600 series radios that allows...
High
Unreviewed
CVE-2024-41153
was published
Oct 29, 2024
Diagnostics command injection vulnerability
High
Unreviewed
CVE-2025-6978
was published
Oct 23, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection...
High
Unreviewed
CVE-2025-34514
was published
Oct 16, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API