GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            13 advisories
        Filter by severity
        
      
      
    
                    
                      Shell Metacharacter Injection in kelredd-pruview
                    
                      
  Critical
                    
                
                      
                        CVE-2013-1947
                      
                      was published
                        for
                        
                          kelredd-pruview
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Creme Fraiche contains OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2013-2090
                      
                      was published
                        for
                        
                          cremefraiche
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Nokogiri Command Injection Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2019-5477
                      
                      was published
                        for
                        
                          nokogiri
                        
                        (RubyGems)
                      Aug 19, 2019 
                    
                  
                    
                      BibTeX-Ruby vulnerable to OS command injection
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10780
                      
                      was published
                        for
                        
                          bibtex-ruby
                        
                        (RubyGems)
                      Feb 14, 2020 
                    
                  
                    
                      Remote shell execution vulnerability in image_processing
                    
                      
  Critical
                    
                
                      
                        CVE-2022-24720
                      
                      was published
                        for
                        
                          image_processing
                        
                        (RubyGems)
                      Mar 1, 2022 
                    
                  
                    
                      Command Injection vulnerability in asciidoctor-include-ext
                    
                      
  Critical
                    
                
                      
                        CVE-2022-24803
                      
                      was published
                        for
                        
                          asciidoctor-include-ext
                        
                        (RubyGems)
                      Mar 31, 2022 
                    
                  
                    
                      smalruby and smalruby-editor vulnerable to OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2017-2096
                      
                      was published
                        for
                        
                          smalruby
                        
                        (RubyGems)
                      May 13, 2022 
                    
                  
                    
                      OS Command Injection in awesome spawn
                    
                      
  Critical
                    
                
                      
                        CVE-2014-0156
                      
                      was published
                        for
                        
                          awesome_spawn
                        
                        (RubyGems)
                      Jul 1, 2022 
                    
                  
                    
                      Code injection in pdf_info
                    
                      
  Critical
                    
                
                      
                        CVE-2022-36231
                      
                      was published
                        for
                        
                          pdf_info
                        
                        (RubyGems)
                      Feb 24, 2023 
                    
                  
                    
                      Foreman Transpilation Enables OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2022-3874
                      
                      was published
                        for
                        
                          foreman
                        
                        (RubyGems)
                      Sep 22, 2023 
                        •
                        
                          withdrawn
                    
                  
                    
                      discordrb OS Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-28102
                      
                      was published
                        for
                        
                          discordrb
                        
                        (RubyGems)
                      Mar 14, 2024 
                    
                  
                    
                      Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53623
                      
                      was published
                        for
                        
                          job-iteration
                        
                        (RubyGems)
                      Jul 14, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API