GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,051
Maven
5,000+
npm
4,791
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,145
Swift
50
Unreviewed advisories
All unreviewed
5,000+
271 advisories
Filter by severity
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the...
Critical
Unreviewed
CVE-2025-70327
was published
Feb 23, 2026
Weblate has an argument injection in management console
Moderate
CVE-2026-24126
was published
for
Weblate
(pip)
Feb 17, 2026
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
Moderate
Unreviewed
CVE-2025-15316
was published
Feb 10, 2026
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
Moderate
Unreviewed
CVE-2025-15315
was published
Feb 10, 2026
Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
Moderate
CVE-2026-24739
was published
for
symfony/process
(Composer)
Jan 28, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-22582
was published
Jan 24, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-22583
was published
Jan 24, 2026
WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2026-0774
was published
Jan 23, 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value...
Critical
Unreviewed
CVE-2026-24061
was published
Jan 21, 2026
Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the...
Moderate
Unreviewed
CVE-2026-23766
was published
Jan 15, 2026
A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity...
High
Unreviewed
CVE-2025-67858
was published
Jan 8, 2026
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')...
Moderate
Unreviewed
CVE-2025-66002
was published
Jan 8, 2026
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a...
Moderate
Unreviewed
CVE-2025-14946
was published
Dec 19, 2025
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Moderate
CVE-2025-68144
was published
for
mcp-server-git
(pip)
Dec 17, 2025
An improper neutralization of argument delimiters in a command vulnerability has been reported to...
Moderate
Unreviewed
CVE-2025-62847
was published
Dec 16, 2025
Easywall 0.3.1 allows authenticated remote command execution via a command injection...
High
Unreviewed
CVE-2024-58275
was published
Dec 4, 2025
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
High
CVE-2025-12613
was published
for
cloudinary
(npm)
Nov 10, 2025
An argument injection vulnerability exists in the affected product that could allow an attacker...
High
Unreviewed
CVE-2025-12556
was published
Nov 6, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-36565
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43905
was published
Oct 7, 2025
Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local...
High
Unreviewed
CVE-2025-59489
was published
Oct 3, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
@conventional-changelog/git-client has Argument Injection vulnerability
Moderate
CVE-2025-59433
was published
for
@conventional-changelog/git-client
(npm)
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API