GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,666 advisories
Filter by severity
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command...
Critical
Unreviewed
CVE-2026-93012
was published
Sep 21, 2026
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection...
Critical
Unreviewed
CVE-2026-80442
was published
Sep 18, 2026
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100...
Critical
Unreviewed
CVE-2026-90822
was published
Sep 17, 2026
A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote...
Critical
Unreviewed
CVE-2026-20306
was published
Sep 16, 2026
A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated,...
Critical
Unreviewed
CVE-2026-20305
was published
Sep 16, 2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an...
Critical
Unreviewed
CVE-2026-73172
was published
Sep 16, 2026
WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in...
Critical
Unreviewed
CVE-2026-40855
was published
Sep 16, 2026
WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi...
Critical
Unreviewed
CVE-2026-58147
was published
Sep 16, 2026
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The...
Critical
Unreviewed
CVE-2026-58146
was published
Sep 16, 2026
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a...
Critical
Unreviewed
CVE-2026-27565
was published
Sep 16, 2026
A privileged attacker can exploit certain operation to execute arbitrary commands with root...
Critical
Unreviewed
CVE-2026-73447
was published
Sep 16, 2026
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that...
Critical
Unreviewed
CVE-2026-91931
was published
Sep 15, 2026
An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing...
Critical
Unreviewed
CVE-2026-89308
was published
Sep 15, 2026
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an...
Critical
Unreviewed
CVE-2026-89010
was published
Sep 11, 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS...
Critical
Unreviewed
CVE-2026-79724
was published
Sep 11, 2026
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated...
Critical
Unreviewed
CVE-2026-65638
was published
Sep 10, 2026
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a...
Critical
Unreviewed
CVE-2026-65639
was published
Sep 10, 2026
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
Critical
Unreviewed
CVE-2026-81467
was published
Sep 10, 2026
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special...
Critical
Unreviewed
CVE-2026-81468
was published
Sep 10, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used...
Critical
Unreviewed
CVE-2026-82004
was published
Sep 8, 2026
Semaphore U: OS Command Injection
Critical
CVE-2026-73294
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 8, 2026
OS command injection vulnerability in Cosminexus Component Container.
This issue affects...
Critical
Unreviewed
CVE-2026-71376
was published
Sep 8, 2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Critical
Unreviewed
CVE-2026-78327
was published
Sep 4, 2026
SadTalker contains an OS command injection vulnerability in the video muxing process where...
Critical
Unreviewed
CVE-2026-85696
was published
Sep 4, 2026
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where...
Critical
Unreviewed
CVE-2026-85672
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API