GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
5,642 advisories
Filter by severity
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Critical
Unreviewed
CVE-2026-93698
was published
Oct 2, 2026
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection....
High
Unreviewed
CVE-2026-71452
was published
Oct 2, 2026
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...
Critical
Unreviewed
CVE-2009-20011
was published
Oct 2, 2026
Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php...
Critical
Unreviewed
CVE-2009-20010
was published
Oct 2, 2026
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection.
...
High
Unreviewed
CVE-2026-71451
was published
Oct 1, 2026
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1....
High
Unreviewed
CVE-2026-84682
was published
Oct 1, 2026
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN...
High
Unreviewed
CVE-2026-102294
was published
Oct 1, 2026
A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due...
Moderate
Unreviewed
CVE-2026-12542
was published
Oct 1, 2026
A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI...
Moderate
Unreviewed
CVE-2026-12545
was published
Oct 1, 2026
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors...
High
Unreviewed
CVE-2026-12540
was published
Oct 1, 2026
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db...
High
Unreviewed
CVE-2026-12541
was published
Oct 1, 2026
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in...
High
Unreviewed
CVE-2026-12405
was published
Oct 1, 2026
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated...
Critical
Unreviewed
CVE-2026-79898
was published
Oct 1, 2026
virtualenv bash and fish activation scripts execute commands embedded in paths
High
CVE-2026-102925
was published
for
virtualenv
(pip)
Oct 1, 2026
virtualenv: Command injection via --prompt in activate.bat (batch activator)
High
CVE-2026-102937
was published
for
virtualenv
(pip)
Oct 1, 2026
An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the...
High
Unreviewed
CVE-2026-76146
was published
Oct 1, 2026
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool...
Critical
Unreviewed
CVE-2026-51870
was published
Sep 30, 2026
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node...
Critical
Unreviewed
CVE-2026-103473
was published
Sep 30, 2026
In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 authenticated users could execute...
High
Unreviewed
CVE-2026-100254
was published
Sep 30, 2026
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal
Moderate
GHSA-97jj-33gv-5xf9
was published
for
league/commonmark
(Composer)
Sep 30, 2026
Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who...
Moderate
Unreviewed
CVE-2026-78229
was published
Sep 30, 2026
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions...
Critical
Unreviewed
CVE-2026-103056
was published
Sep 30, 2026
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool ...
Moderate
Unreviewed
CVE-2026-79535
was published
Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled...
High
Unreviewed
CVE-2026-100292
was published
Sep 29, 2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME...
High
Unreviewed
CVE-2026-84422
was published
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API