GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
88 advisories
Filter by severity
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
Moderate
CVE-2026-50014
was published
for
pnpm
(npm)
Jun 26, 2026
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
Moderate
GHSA-5vwr-qchf-q4pf
was published
for
@cyclonedx/cdxgen
(npm)
Jun 26, 2026
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary...
Moderate
Unreviewed
CVE-2026-11968
was published
Jun 24, 2026
MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
Moderate
CVE-2026-47250
was published
for
mcp-server-kubernetes
(npm)
Jun 5, 2026
Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
Moderate
CVE-2026-45068
was published
for
symfony/mailer
(Composer)
May 27, 2026
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
Moderate
CVE-2026-44210
was published
for
github.com/kata-containers/kata-containers
(Go)
May 26, 2026
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
Moderate
GHSA-m9p2-fxp5-v3fp
was published
for
diesel
(Rust)
May 19, 2026
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
Moderate
CVE-2026-44968
was published
for
dbt-mcp
(pip)
May 14, 2026
An improper neutralization of argument delimiters in a command ('argument injection')...
Moderate
Unreviewed
CVE-2026-25690
was published
May 12, 2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM...
Moderate
Unreviewed
CVE-2025-40948
was published
May 12, 2026
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via...
Moderate
Unreviewed
CVE-2026-45181
was published
May 10, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Moderate
CVE-2026-6437
was published
for
github.com/kubernetes-sigs/aws-efs-csi-driver
(Go)
Apr 18, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0...
Moderate
Unreviewed
CVE-2026-35153
was published
Apr 17, 2026
skilleton has improper input handling in repository/path processing
Moderate
GHSA-5g3j-89fr-r2vp
was published
for
skilleton
(npm)
Apr 8, 2026
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters...
Moderate
Unreviewed
CVE-2026-23924
was published
Mar 24, 2026
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the...
Moderate
Unreviewed
CVE-2026-4438
was published
Mar 20, 2026
Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
GHSA-g87j-gm7p-6vw2
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo...
Moderate
Unreviewed
CVE-2026-1715
was published
Mar 11, 2026
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in...
Moderate
Unreviewed
CVE-2026-1717
was published
Mar 11, 2026
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo...
Moderate
Unreviewed
CVE-2026-1716
was published
Mar 11, 2026
An improper neutralization of argument delimiters in a command ('argument injection')...
Moderate
Unreviewed
CVE-2026-25689
was published
Mar 10, 2026
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and...
Moderate
Unreviewed
CVE-2026-20016
was published
Mar 4, 2026
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local...
Moderate
Unreviewed
CVE-2026-20063
was published
Mar 4, 2026
OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
CVE-2026-29608
was published
for
openclaw
(npm)
Mar 3, 2026
Weblate has an argument injection in management console
Moderate
CVE-2026-24126
was published
for
Weblate
(pip)
Feb 17, 2026
ProTip!
Advisories are also available from the
GraphQL API