GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
244 advisories
Filter by severity
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line...
High
Unreviewed
CVE-2026-64624
was published
Jul 21, 2026
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured...
Critical
Unreviewed
CVE-2026-61459
was published
Jul 10, 2026
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH...
High
Unreviewed
CVE-2026-47829
was published
Jul 9, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-40047
was published
Jul 6, 2026
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability...
High
Unreviewed
CVE-2026-14459
was published
Jul 3, 2026
A flaw was found in the vscode-java extension, which provides Java language support for Visual...
High
Unreviewed
CVE-2026-12856
was published
Jun 29, 2026
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary...
Moderate
Unreviewed
CVE-2026-11968
was published
Jun 24, 2026
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM,...
Critical
Unreviewed
CVE-2026-47365
was published
Jun 12, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2026-53694
was published
Jun 10, 2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release...
High
Unreviewed
CVE-2026-41013
was published
Jun 1, 2026
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection...
High
Unreviewed
CVE-2026-49373
was published
May 29, 2026
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote...
High
Unreviewed
CVE-2026-47114
was published
May 21, 2026
An improper neutralization of argument delimiters in a command ('argument injection')...
Moderate
Unreviewed
CVE-2026-25690
was published
May 12, 2026
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection...
Critical
Unreviewed
CVE-2026-31230
was published
May 12, 2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM...
Moderate
Unreviewed
CVE-2025-40948
was published
May 12, 2026
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via...
Moderate
Unreviewed
CVE-2026-45181
was published
May 10, 2026
A hidden console command is vulnerable to command injection
flaw when control characters are...
High
Unreviewed
CVE-2026-7865
was published
May 5, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0...
Moderate
Unreviewed
CVE-2026-35153
was published
Apr 17, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo...
High
Unreviewed
CVE-2026-4145
was published
Apr 15, 2026
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability...
Critical
Unreviewed
CVE-2026-2449
was published
Apr 14, 2026
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be...
High
Unreviewed
CVE-2026-4786
was published
Apr 14, 2026
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to...
High
Unreviewed
CVE-2026-0634
was published
Apr 2, 2026
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF...
High
Unreviewed
CVE-2026-29954
was published
Mar 30, 2026
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters...
Moderate
Unreviewed
CVE-2026-23924
was published
Mar 24, 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
Critical
Unreviewed
CVE-2026-2298
was published
Mar 23, 2026
ProTip!
Advisories are also available from the
GraphQL API