GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,986 advisories
Filter by severity
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write...
Moderate
Unreviewed
CVE-2025-55824
was published
Sep 5, 2025
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function...
Moderate
Unreviewed
CVE-2025-9752
was published
Sep 4, 2025
It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge...
High
Unreviewed
CVE-2025-7388
was published
Sep 4, 2025
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
Low
GHSA-vxmw-7h4f-hqxh
was published
for
pypa/gh-action-pypi-publish
(GitHub Actions)
Sep 4, 2025
A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability...
Moderate
Unreviewed
CVE-2025-9935
was published
Sep 4, 2025
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function...
Moderate
Unreviewed
CVE-2025-9934
was published
Sep 4, 2025
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
High
CVE-2025-58358
was published
for
mcp-markdownify-server
(npm)
Sep 2, 2025
Command Injection via sonarqube-scan-action GitHub Action
High
CVE-2025-58178
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 2, 2025
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the...
Moderate
Unreviewed
CVE-2025-50755
was published
Sep 2, 2025
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to...
Moderate
Unreviewed
CVE-2024-48705
was published
Sep 2, 2025
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the...
Moderate
Unreviewed
CVE-2025-50757
was published
Sep 2, 2025
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker...
Low
Unreviewed
CVE-2025-44015
was published
Aug 29, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
High
Unreviewed
CVE-2025-30264
was published
Aug 29, 2025
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote...
High
Unreviewed
CVE-2025-29887
was published
Aug 29, 2025
A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an...
Moderate
Unreviewed
CVE-2025-9603
was published
Aug 29, 2025
An Improper Input Validation in UISP Application could allow a Command Injection by a malicious...
Low
Unreviewed
CVE-2025-48979
was published
Aug 29, 2025
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the...
Moderate
Unreviewed
CVE-2025-9581
was published
Aug 28, 2025
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file ...
Moderate
Unreviewed
CVE-2025-9582
was published
Aug 28, 2025
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2025-9579
was published
Aug 28, 2025
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9580
was published
Aug 28, 2025
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-9575
was published
Aug 28, 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the...
Critical
Unreviewed
CVE-2025-50428
was published
Aug 27, 2025
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface...
High
Unreviewed
CVE-2025-50989
was published
Aug 27, 2025
ProTip!
Advisories are also available from the
GraphQL API