GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,331
Erlang
31
GitHub Actions
21
Go
2,093
Maven
5,000+
npm
3,756
NuGet
678
pip
3,443
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
206 advisories
Filter by severity
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29405
was published
Jun 8, 2023
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via...
Moderate
Unreviewed
CVE-2023-26782
was published
Apr 28, 2023
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root...
Moderate
Unreviewed
CVE-2022-37705
was published
Apr 16, 2023
CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument...
High
Unreviewed
CVE-2023-25356
was published
Apr 4, 2023
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet...
High
Unreviewed
CVE-2022-40677
was published
Feb 16, 2023
Command injection in Git package in Wrangler
High
CVE-2022-31249
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Command injection in Rancher Git package
Moderate
CVE-2022-43758
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Froxlor vulnerable to Argument Injection
Moderate
CVE-2022-4864
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
Critical
Unreviewed
CVE-2022-47926
was published
Dec 22, 2022
A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions), SIMATIC WinCC OA V3...
Moderate
Unreviewed
CVE-2022-44731
was published
Dec 13, 2022
phpxmlrpc vulnerable to argument injection
Moderate
GHSA-q7qq-9gx2-ggxv
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Dec 2, 2022
CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was...
High
Unreviewed
CVE-2022-23740
was published
Nov 23, 2022
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection...
Critical
Unreviewed
CVE-2022-45062
was published
Nov 9, 2022
Gitea vulnerable to Argument Injection
Critical
CVE-2022-42968
was published
for
github.com/go-gitea/gitea
(Go)
Oct 16, 2022
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS...
Moderate
Unreviewed
CVE-2022-3140
was published
Oct 12, 2022
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2022-20930
was published
Oct 1, 2022
Poetry Argument Injection can lead to Local Code Execution
High
CVE-2022-36069
was published
for
poetry
(pip)
Sep 16, 2022
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used...
Critical
Unreviewed
CVE-2022-1399
was published
Aug 18, 2022
mc-kill-port vulnerable to Arbitrary Command Execution via kill function
High
CVE-2022-25973
was published
for
mc-kill-port
(npm)
Aug 11, 2022
The Settings application has an argument injection vulnerability. Successful exploitation of this...
High
Unreviewed
CVE-2022-37005
was published
Aug 11, 2022
Apache Hadoop argument injection vulnerability
Critical
CVE-2022-25168
was published
for
org.apache.hadoop:hadoop-common
(Maven)
Aug 5, 2022
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
High
Unreviewed
CVE-2022-36322
was published
Jul 21, 2022
Codecov does not sanitize gcov arguments
High
CVE-2019-10800
was published
for
codecov
(pip)
Jul 14, 2022
paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment...
Moderate
Unreviewed
CVE-2022-31246
was published
Jun 18, 2022
ProTip!
Advisories are also available from the
GraphQL API