GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
226 advisories
Filter by severity
Remote Code Execution in Spring Framework
Critical
CVE-2022-22965
was published
for
org.springframework.boot:spring-boot-starter-web
(Maven)
Mar 31, 2022
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to...
Critical
Unreviewed
CVE-2022-3236
was published
Sep 25, 2022
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates...
Critical
Unreviewed
CVE-2023-24540
was published
May 11, 2023
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink...
Critical
Unreviewed
CVE-2024-21797
was published
Jan 14, 2025
A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000...
Critical
Unreviewed
CVE-2024-36295
was published
Jan 14, 2025
A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink...
Critical
Unreviewed
CVE-2024-34544
was published
Jan 14, 2025
A command execution vulnerability exists in the update_filter_url.sh functionality of Wavlink...
Critical
Unreviewed
CVE-2024-39604
was published
Jan 14, 2025
Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of...
Critical
Unreviewed
CVE-2024-39785
was published
Jan 14, 2025
Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of...
Critical
Unreviewed
CVE-2024-39784
was published
Jan 14, 2025
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29405
was published
Jun 8, 2023
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It...
Critical
Unreviewed
CVE-2024-10914
was published
Nov 6, 2024
Langchain SQL Injection vulnerability
Critical
CVE-2023-32785
was published
for
langchain
(pip)
Oct 21, 2023
SaltStack Salt is vulnerable to shell injection via ProxyCommand argument
Critical
CVE-2021-3197
was published
for
salt
(pip)
May 24, 2022
pwntools Server-Side Template Injection (SSTI) vulnerability
Critical
CVE-2020-28468
was published
for
pwntools
(pip)
Apr 20, 2021
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
Critical
CVE-2015-3253
was published
for
org.codehaus.groovy:groovy
(Maven)
May 13, 2022
Arbitrary expression injection in Pillow
Critical
CVE-2022-22817
was published
for
Pillow
(pip)
Jan 12, 2022
Searchor CLI's Search vulnerable to Arbitrary Code using Eval
Critical
CVE-2023-43364
was published
for
searchor
(pip)
Sep 25, 2023
llama-index vulnerable to arbitrary code execution
Critical
CVE-2023-39662
was published
for
llama-index
(pip)
Aug 15, 2023
LangChain vulnerable to code injection
Critical
CVE-2023-29374
was published
for
langchain
(pip)
Apr 5, 2023
Command injection in libvcs and vcspull
Critical
CVE-2022-21187
was published
for
libvcs
(pip)
Mar 15, 2022
LangChain vulnerable to arbitrary code execution
Critical
CVE-2023-38896
was published
for
langchain
(pip)
Aug 15, 2023
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI...
Critical
Unreviewed
CVE-2023-39213
was published
Aug 9, 2023
LangChain vulnerable to arbitrary code execution
Critical
CVE-2023-39659
was published
for
langchain
(pip)
Aug 15, 2023
DataEase's H2 datasource has a remote command execution risk
Critical
CVE-2024-46997
was published
for
io.dataease:common
(Maven)
Sep 23, 2024
ProTip!
Advisories are also available from the
GraphQL API