GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,633
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
855 advisories
Filter by severity
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27657
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27678
was published
Mar 5, 2025
An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows...
Critical
Unreviewed
CVE-2024-29500
was published
Apr 10, 2024
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded...
Critical
Unreviewed
CVE-2025-3114
was published
Apr 9, 2025
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a...
Critical
Unreviewed
CVE-2025-28146
was published
Apr 4, 2025
In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open...
Critical
Unreviewed
CVE-2025-3579
was published
Apr 15, 2025
Bundler allows attacker to inject arbitrary code via secondary Gem source
Critical
CVE-2016-7954
was published
for
bundler
(RubyGems)
May 14, 2022
phpMyAdmin Code Injection vulnerability
Critical
CVE-2016-5734
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly...
Critical
Unreviewed
CVE-2025-1782
was published
Apr 14, 2025
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP...
Critical
Unreviewed
CVE-2015-5721
was published
May 17, 2022
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS)...
Critical
Unreviewed
CVE-2022-48198
was published
Jan 1, 2023
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto...
Critical
Unreviewed
CVE-2024-25096
was published
Apr 3, 2024
Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
CVE-2025-3248
was published
for
langflow
(pip)
Apr 7, 2025
Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over...
Critical
Unreviewed
CVE-2025-3115
was published
Apr 9, 2025
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function...
Critical
Unreviewed
CVE-2025-27429
was published
Apr 8, 2025
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a...
Critical
Unreviewed
CVE-2025-31330
was published
Apr 8, 2025
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2025-29064
was published
Apr 3, 2025
Netwrix Password Secure through 9.2 allows command injection.
Critical
Unreviewed
CVE-2025-26818
was published
Apr 3, 2025
pgAdmin 4 Vulnerable to Remote Code Execution
Critical
CVE-2025-2945
was published
for
pgadmin4
(pip)
Apr 3, 2025
The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all...
Critical
Unreviewed
CVE-2024-13645
was published
Apr 4, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54804
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi...
Critical
Unreviewed
CVE-2024-54806
was published
Mar 31, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in...
Critical
Unreviewed
CVE-2024-54807
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54805
was published
Mar 31, 2025
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a...
Critical
Unreviewed
CVE-2024-54803
was published
Mar 31, 2025
ProTip!
Advisories are also available from the
GraphQL API