GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,742
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,074 advisories
Filter by severity
Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent tool
Critical
CVE-2025-67511
was published
for
cai-framework
(pip)
Dec 9, 2025
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the...
Critical
Unreviewed
CVE-2025-60854
was published
Dec 2, 2025
iStats contains an insecure XPC service that allows local, unprivileged users to escalate their...
Critical
Unreviewed
CVE-2025-11921
was published
Nov 24, 2025
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the...
Critical
Unreviewed
CVE-2025-58428
was published
Oct 23, 2025
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command...
Critical
Unreviewed
CVE-2025-10020
was published
Oct 21, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59737
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59735
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59736
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59738
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59739
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59740
was published
Oct 2, 2025
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59741
was published
Oct 2, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61044
was published
Oct 1, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61045
was published
Oct 1, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system...
Critical
Unreviewed
CVE-2025-59815
was published
Sep 25, 2025
This vulnerability allows attackers to execute arbitrary commands on the underlying system....
Critical
Unreviewed
CVE-2025-59817
was published
Sep 25, 2025
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor...
Critical
Unreviewed
CVE-2025-10035
was published
Sep 19, 2025
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2025-52053
was published
Sep 15, 2025
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application....
Critical
Unreviewed
CVE-2025-10364
was published
Sep 12, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated...
Critical
Unreviewed
CVE-2025-57633
was published
Sep 9, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API