GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,145 advisories
Filter by severity
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the...
Critical
Unreviewed
CVE-2026-38835
was published
Apr 21, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
Critical
CVE-2026-41497
was published
for
praisonai
(pip)
Apr 17, 2026
electerm: electerm_install_script_CommandInjection Vulnerability Report
Critical
CVE-2026-41500
was published
for
electerm
(npm)
Apr 16, 2026
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote...
Critical
Unreviewed
CVE-2026-20186
was published
Apr 15, 2026
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to...
Critical
Unreviewed
CVE-2026-20147
was published
Apr 15, 2026
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality
Critical
CVE-2026-30625
was published
for
upsonic
(pip)
Apr 15, 2026
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to...
Critical
Unreviewed
CVE-2026-31170
was published
Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs
Critical
CVE-2026-35580
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive...
Critical
Unreviewed
CVE-2026-31059
was published
Apr 6, 2026
pymetasploit3 vulnerable to command injection in console.run_module_with_output()
Critical
CVE-2026-5463
was published
for
pymetasploit3
(pip)
Apr 3, 2026
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3...
Critical
Unreviewed
CVE-2024-43028
was published
Apr 1, 2026
In its design for automatic terminal command execution, Sixth offers two options: Execute safe...
Critical
Unreviewed
CVE-2026-30310
was published
Mar 31, 2026
MLflow Command Injection vulnerability
Critical
CVE-2025-15379
was published
for
mlflow
(pip)
Mar 30, 2026
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Critical
CVE-2026-34243
was published
for
njzjz/wenxian
(GitHub Actions)
Mar 29, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft...
Critical
Unreviewed
CVE-2026-32194
was published
Mar 20, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26793
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26791
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26795
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities...
Critical
Unreviewed
CVE-2026-26792
was published
Mar 12, 2026
@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters
Critical
CVE-2026-31862
was published
for
@siteboon/claudecodeui
(npm)
Mar 11, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Critical
GHSA-5wp8-q9mx-8jx8
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2...
Critical
Unreviewed
CVE-2026-2333
was published
Feb 20, 2026
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying...
Critical
Unreviewed
CVE-2025-59818
was published
Feb 4, 2026
Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements...
Critical
Unreviewed
CVE-2025-26385
was published
Jan 30, 2026
ProTip!
Advisories are also available from the
GraphQL API