GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,933
Erlang
39
GitHub Actions
38
Go
2,595
Maven
5,000+
npm
4,247
NuGet
754
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,250 advisories
Filter by severity
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection...
Critical
Unreviewed
CVE-2016-15048
was published
Oct 22, 2025
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
Critical
Unreviewed
CVE-2025-6542
was published
Oct 21, 2025
A command injection vulnerability may be exploited after the admin's authentication on the web...
Critical
Unreviewed
CVE-2025-7850
was published
Oct 21, 2025
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command...
Critical
Unreviewed
CVE-2018-25118
was published
Oct 21, 2025
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing...
Critical
Unreviewed
CVE-2025-11900
was published
Oct 17, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection...
Critical
Unreviewed
CVE-2025-34513
was published
Oct 16, 2025
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7304
was published
Oct 15, 2025
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7311
was published
Oct 15, 2025
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform...
Critical
Unreviewed
CVE-2025-9976
was published
Oct 13, 2025
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F...
Critical
Unreviewed
CVE-2025-60964
was published
Oct 6, 2025
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F...
Critical
Unreviewed
CVE-2025-60965
was published
Oct 6, 2025
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F...
Critical
Unreviewed
CVE-2025-60957
was published
Oct 6, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59735
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59737
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59739
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59740
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59738
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59736
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59741
was published
Oct 2, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61045
was published
Oct 1, 2025
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to...
Critical
Unreviewed
CVE-2025-10659
was published
Sep 30, 2025
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
Critical
Unreviewed
CVE-2025-9762
was published
Sep 30, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware...
Critical
Unreviewed
CVE-2025-30247
was published
Sep 29, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Critical
Unreviewed
CVE-2025-11005
was published
Sep 25, 2025
ProTip!
Advisories are also available from the
GraphQL API