GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
138 advisories
Filter by severity
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd...
High
Unreviewed
CVE-2025-32455
was published
Jun 8, 2025
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the...
High
Unreviewed
CVE-2025-32456
was published
Jun 8, 2025
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the...
High
Unreviewed
CVE-2025-32458
was published
Jun 8, 2025
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the...
High
Unreviewed
CVE-2025-32459
was published
Jun 8, 2025
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2025-3945
was published
May 22, 2025
Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2...
High
Unreviewed
CVE-2025-1712
was published
May 21, 2025
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of...
High
Unreviewed
CVE-2025-0065
was published
Jan 28, 2025
A user with administrator privileges can perform command injection
High
Unreviewed
CVE-2024-9131
was published
Jan 11, 2025
Gogs allows argument Injection when tagging new releases
High
CVE-2024-39933
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command (...
High
Unreviewed
CVE-2024-51532
was published
Dec 19, 2024
Laravel environment manipulation via query string
High
CVE-2024-52301
was published
for
laravel/framework
(Composer)
Nov 12, 2024
Duplicate Advisory: Gogs allows argument injection during the tagging of a new release
High
GHSA-8mm6-wmpp-mmm3
was published
for
github.com/gogs/gogs
(Go)
Jul 4, 2024
•
withdrawn
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2023-50232
was published
May 3, 2024
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-44452
was published
May 3, 2024
A server side request forgery vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2024-3684
was published
Apr 19, 2024
A remote, unauthenticated attacker may be able to send crafted messages
to the web server of the...
High
Unreviewed
CVE-2024-22182
was published
Mar 1, 2024
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments....
High
Unreviewed
CVE-2023-47804
was published
Dec 29, 2023
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2023-46681
was published
Dec 26, 2023
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local...
High
Unreviewed
CVE-2023-0633
was published
Sep 25, 2023
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation...
High
Unreviewed
CVE-2023-20224
was published
Aug 17, 2023
Apache Airflow ODBC Provider Argument Injection vulnerability
High
CVE-2023-34395
was published
for
apache-airflow-providers-odbc
(pip)
Jun 27, 2023
CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument...
High
Unreviewed
CVE-2023-25356
was published
Apr 4, 2023
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet...
High
Unreviewed
CVE-2022-40677
was published
Feb 16, 2023
Command injection in Git package in Wrangler
High
CVE-2022-31249
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team...
High
Unreviewed
CVE-2022-46883
was published
Dec 22, 2022
ProTip!
Advisories are also available from the
GraphQL API