GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
Fix for authenticated remote code execution through layout update
High
CVE-2021-41144
was published
for
openmage/magento-lts
(Composer)
Jan 27, 2023
Fix for arbitrary file deletion in customer media allows for remote code execution
High
CVE-2021-41143
was published
for
openmage/magento-lts
(Composer)
Jan 27, 2023
Fix for arbitrary command execution in custom layout update through blocks
High
CVE-2021-39217
was published
for
openmage/magento-lts
(Composer)
Jan 27, 2023
Command Injection in puppet-facter
High
CVE-2022-25350
was published
for
puppet-facter
(npm)
Jan 26, 2023
Command injection in Git package in Wrangler
High
CVE-2022-31249
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Froxlor vulnerable to Command Injection
High
CVE-2023-0315
was published
for
froxlor/froxlor
(Composer)
Jan 16, 2023
window-control vulnerable to Command Injection due to improper input sanitization
High
CVE-2022-25926
was published
for
window-control
(npm)
Jan 4, 2023
Apache Kylin vulnerable to Command injection by Useless configuration
High
CVE-2022-43396
was published
for
org.apache.kylin:kylin
(Maven)
Dec 30, 2022
Powerline Gitstatus vulnerable to arbitrary code execution
High
CVE-2022-42906
was published
for
powerline-gitstatus
(pip)
Oct 13, 2022
NuProcess vulnerable to command-line injection through insertion of NUL character(s)
High
CVE-2022-39243
was published
for
com.zaxxer:nuprocess
(Maven)
Sep 30, 2022
Apache James vulnerable to buffering attack
High
CVE-2022-28220
was published
for
org.apache.james:james-server
(Maven)
Sep 9, 2022
Improper token validation leading to code execution in Teleport
High
CVE-2022-36633
was published
for
github.com/gravitational/teleport
(Go)
Aug 25, 2022
git-archive vulnerable to Command Injection via exports function
High
CVE-2020-28422
was published
for
git-archive
(npm)
Jul 26, 2022
OS Command Injection in git-promise
High
CVE-2022-24376
was published
for
git-promise
(npm)
Jun 11, 2022
furlongm openvpn-monitor command injection
High
CVE-2021-31605
was published
for
openvpn-monitor
(pip)
May 24, 2022
Drupal Core Arbitrary PHP code execution vulnerability
High
CVE-2020-13664
was published
for
drupal/core
(Composer)
May 24, 2022
SaltStack Salt command injection via a crafted process name
High
CVE-2020-28243
was published
for
salt
(pip)
May 24, 2022
Dolibarr authenticated Remote Code Execution
High
CVE-2020-35136
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Cobbler subject to Command Injection
High
CVE-2012-2395
was published
for
cobbler
(pip)
May 17, 2022
Improper Neutralization of Special Elements used in a Command in FitNesse Wiki
High
CVE-2014-1216
was published
for
org.fitnesse:fitnesse
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API