GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,666 advisories
Filter by severity
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Critical
GHSA-jqmf-mx4f-hfr6
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
A specially crafted HTTP POST request to the web administration interface allows an...
Critical
Unreviewed
CVE-2026-75937
was published
Oct 2, 2026
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Critical
Unreviewed
CVE-2026-93698
was published
Oct 2, 2026
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...
Critical
Unreviewed
CVE-2009-20011
was published
Oct 2, 2026
Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php...
Critical
Unreviewed
CVE-2009-20010
was published
Oct 2, 2026
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated...
Critical
Unreviewed
CVE-2026-79898
was published
Oct 1, 2026
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool...
Critical
Unreviewed
CVE-2026-51870
was published
Sep 30, 2026
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node...
Critical
Unreviewed
CVE-2026-103473
was published
Sep 30, 2026
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions...
Critical
Unreviewed
CVE-2026-103056
was published
Sep 30, 2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export...
Critical
Unreviewed
CVE-2026-84436
was published
Sep 29, 2026
An OS command injection vulnerability in the WatchGuard AP internal API service allows an...
Critical
Unreviewed
CVE-2026-86102
was published
Sep 28, 2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Critical
Unreviewed
CVE-2026-100382
was published
Sep 26, 2026
The affected products are vulnerable to command injection attack that could allow an...
Critical
Unreviewed
CVE-2026-93289
was published
Sep 24, 2026
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web...
Critical
Unreviewed
CVE-2026-13249
was published
Sep 24, 2026
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially...
Critical
Unreviewed
CVE-2026-6721
was published
Sep 23, 2026
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with...
Critical
Unreviewed
CVE-2026-87898
was published
Sep 23, 2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code...
Critical
Unreviewed
CVE-2026-19599
was published
Sep 23, 2026
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection...
Critical
Unreviewed
CVE-2026-43641
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80152
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80151
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80145
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80144
was published
Sep 22, 2026
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all...
Critical
Unreviewed
CVE-2026-80143
was published
Sep 22, 2026
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code...
Critical
Unreviewed
CVE-2026-95675
was published
Sep 22, 2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote...
Critical
Unreviewed
CVE-2026-74849
was published
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API