GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value...
Critical
Unreviewed
CVE-2026-24061
was published
Jan 21, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-22582
was published
Jan 24, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-22583
was published
Jan 24, 2026
A vulnerability was discovered where specific command line arguments are not properly discarded...
Critical
Unreviewed
CVE-2019-9794
was published
May 24, 2022
Remote code execution in PHPMailer
Critical
CVE-2016-10033
was published
for
phpmailer/phpmailer
(Composer)
Mar 5, 2020
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing...
Critical
Unreviewed
CVE-2024-35307
was published
Jun 10, 2024
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to...
Critical
Unreviewed
CVE-2022-28391
was published
Apr 4, 2022
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service ...
Critical
Unreviewed
CVE-2021-26937
was published
May 24, 2022
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection...
Critical
Unreviewed
CVE-2022-45062
was published
Nov 9, 2022
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the...
Critical
Unreviewed
CVE-2024-47516
was published
Mar 26, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
Gogs has an argument Injection in the built-in SSH server
Critical
CVE-2024-39930
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930
Critical
GHSA-p69r-v3h4-rj4f
was published
for
github.com/gogs/gogs
(Go)
Jul 4, 2024
•
withdrawn
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated...
Critical
Unreviewed
CVE-2024-11633
was published
Dec 10, 2024
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29405
was published
Jun 8, 2023
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti...
Critical
Unreviewed
CVE-2024-38656
was published
Nov 13, 2024
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti...
Critical
Unreviewed
CVE-2024-39711
was published
Nov 13, 2024
Argument injection in Ivanti Connect Secure before version 22.7R2 and 9.1R18.7 and Ivanti Policy...
Critical
Unreviewed
CVE-2024-39710
was published
Nov 13, 2024
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti...
Critical
Unreviewed
CVE-2024-39712
was published
Nov 13, 2024
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure...
Critical
Unreviewed
CVE-2024-38655
was published
Nov 13, 2024
Argument injection in python-libnmap
Critical
CVE-2022-30284
was published
for
python-libnmap
(pip)
May 6, 2022
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0)....
Critical
Unreviewed
CVE-2024-47553
was published
Oct 8, 2024
The product allows user input to control or influence paths or file
names that are used in...
Critical
Unreviewed
CVE-2024-3980
was published
Aug 27, 2024
ProTip!
Advisories are also available from the
GraphQL API