GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,895
Erlang
38
GitHub Actions
38
Go
2,558
Maven
5,000+
npm
4,232
NuGet
751
pip
4,001
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,036 advisories
Filter by severity
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
High
CVE-2025-59419
was published
for
io.netty:netty-codec-smtp
(Maven)
Oct 15, 2025
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and...
High
Unreviewed
CVE-2025-53868
was published
Oct 15, 2025
When a user attempts to initialize the rSeries FIPS module using a password with special shell...
Moderate
Unreviewed
CVE-2025-60013
was published
Oct 15, 2025
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7304
was published
Oct 15, 2025
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7311
was published
Oct 15, 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2024-48891
was published
Oct 14, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10243
was published
Oct 14, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10242
was published
Oct 14, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High
Unreviewed
CVE-2025-5946
was published
Oct 14, 2025
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12...
High
Unreviewed
CVE-2025-10985
was published
Oct 14, 2025
Two improper neutralization of special elements used in an OS command ('OS Command Injection')...
High
Unreviewed
CVE-2025-47856
was published
Oct 14, 2025
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform...
Critical
Unreviewed
CVE-2025-9976
was published
Oct 13, 2025
EMCLI contains a high severity vulnerability where improper neutralization of special elements...
High
Unreviewed
CVE-2025-0636
was published
Oct 13, 2025
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to...
High
Unreviewed
CVE-2016-15047
was published
Oct 9, 2025
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS...
Moderate
Unreviewed
CVE-2025-60006
was published
Oct 9, 2025
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with...
High
Unreviewed
CVE-2025-10239
was published
Oct 9, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows...
High
Unreviewed
CVE-2025-57457
was published
Oct 8, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36566
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36569
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36567
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43908
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43890
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43906
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43911
was published
Oct 7, 2025
ProTip!
Advisories are also available from the
GraphQL API