GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,473
Maven
5,000+
npm
4,091
NuGet
734
pip
3,907
Pub
12
RubyGems
944
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,852 advisories
Filter by severity
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-9575
was published
Aug 28, 2025
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9528
was published
Aug 27, 2025
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface...
High
Unreviewed
CVE-2025-50989
was published
Aug 27, 2025
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is...
Moderate
Unreviewed
CVE-2025-9424
was published
Aug 26, 2025
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2025-50722
was published
Aug 26, 2025
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C...
Moderate
Unreviewed
CVE-2025-29519
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29522
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29523
was published
Aug 26, 2025
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet...
Moderate
Unreviewed
CVE-2025-44179
was published
Aug 26, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
Moderate
Unreviewed
CVE-2025-29517
was published
Aug 25, 2025
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command...
High
Unreviewed
CVE-2025-29516
was published
Aug 25, 2025
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9387
was published
Aug 24, 2025
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was...
Moderate
Unreviewed
CVE-2025-55637
was published
Aug 22, 2025
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute...
Critical
Unreviewed
CVE-2025-57105
was published
Aug 22, 2025
Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command (...
High
Unreviewed
CVE-2025-41451
was published
Aug 22, 2025
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an...
Moderate
Unreviewed
CVE-2025-51818
was published
Aug 21, 2025
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a...
Critical
Unreviewed
CVE-2025-24285
was published
Aug 21, 2025
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a...
High
Unreviewed
CVE-2025-48978
was published
Aug 21, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and...
Moderate
Unreviewed
CVE-2025-9244
was published
Aug 20, 2025
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email...
Moderate
Unreviewed
CVE-2025-57733
was published
Aug 20, 2025
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of...
Moderate
Unreviewed
CVE-2025-9176
was published
Aug 20, 2025
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9174
was published
Aug 20, 2025
An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData...
Moderate
Unreviewed
CVE-2025-52337
was published
Aug 19, 2025
Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie...
Moderate
Unreviewed
CVE-2025-50891
was published
Aug 19, 2025
ProTip!
Advisories are also available from the
GraphQL API