GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
58
GitHub Actions
50
Go
3,799
Maven
5,000+
npm
5,000+
NuGet
938
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,351
Swift
54
Unreviewed advisories
All unreviewed
5,000+
1,127 advisories
Filter by severity
An administrative user with access to configure webhooks can execute arbitrary commands by...
Critical
Unreviewed
CVE-2026-8431
was published
May 12, 2026
Improper neutralization of special elements used in a command ('command injection') in Azure...
Critical
Unreviewed
CVE-2026-35428
was published
May 8, 2026
TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and...
Critical
Unreviewed
CVE-2026-36841
was published
Apr 29, 2026
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is...
Critical
Unreviewed
CVE-2026-31255
was published
Apr 27, 2026
A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl...
Critical
Unreviewed
CVE-2026-30352
was published
Apr 27, 2026
electerm has Command Injection via runLinux funtion
Critical
CVE-2026-41501
was published
for
electerm
(npm)
Apr 24, 2026
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Critical
GHSA-wpqr-6v78-jr5g
was published
for
@google/gemini-cli
(GitHub Actions)
Apr 24, 2026
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to...
Critical
Unreviewed
CVE-2026-31175
was published
Apr 23, 2026
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2026-38835
was published
Apr 21, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
Critical
CVE-2026-41497
was published
for
praisonai
(pip)
Apr 17, 2026
electerm: electerm_install_script_CommandInjection Vulnerability Report
Critical
CVE-2026-41500
was published
for
electerm
(npm)
Apr 16, 2026
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to...
Critical
Unreviewed
CVE-2026-20147
was published
Apr 15, 2026
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote...
Critical
Unreviewed
CVE-2026-20186
was published
Apr 15, 2026
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality
Critical
CVE-2026-30625
was published
for
upsonic
(pip)
Apr 15, 2026
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to...
Critical
Unreviewed
CVE-2026-31170
was published
Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs
Critical
CVE-2026-35580
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive...
Critical
Unreviewed
CVE-2026-31059
was published
Apr 6, 2026
pymetasploit3 vulnerable to command injection in console.run_module_with_output()
Critical
CVE-2026-5463
was published
for
pymetasploit3
(pip)
Apr 3, 2026
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3...
Critical
Unreviewed
CVE-2024-43028
was published
Apr 1, 2026
In its design for automatic terminal command execution, Sixth offers two options: Execute safe...
Critical
Unreviewed
CVE-2026-30310
was published
Mar 31, 2026
MLflow Command Injection vulnerability
Critical
CVE-2025-15379
was published
for
mlflow
(pip)
Mar 30, 2026
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Critical
CVE-2026-34243
was published
for
njzjz/wenxian
(GitHub Actions)
Mar 29, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft...
Critical
Unreviewed
CVE-2026-32194
was published
Mar 20, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26793
was published
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API