GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
886 advisories
Filter by severity
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up...
Moderate
Unreviewed
CVE-2026-18641
was published
Aug 3, 2026
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2026-18587
was published
Aug 3, 2026
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger...
Moderate
Unreviewed
CVE-2026-16629
was published
Jul 23, 2026
Improper neutralization of special elements used in a command ('command injection') in Outlook...
Moderate
Unreviewed
CVE-2026-55145
was published
Jul 14, 2026
A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of...
Moderate
Unreviewed
CVE-2026-15487
was published
Jul 12, 2026
A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function...
Moderate
Unreviewed
CVE-2026-15486
was published
Jul 12, 2026
A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-15485
was published
Jul 12, 2026
A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this...
Moderate
Unreviewed
CVE-2026-15033
was published
Jul 8, 2026
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
Moderate
CVE-2026-53533
was published
for
aiosmtplib
(pip)
Jul 7, 2026
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the...
Moderate
Unreviewed
CVE-2026-14802
was published
Jul 6, 2026
An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set...
Moderate
Unreviewed
CVE-2026-38142
was published
Jul 1, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft...
Moderate
Unreviewed
CVE-2026-42895
was published
Jun 19, 2026
Net::IMAP: Command Injection via ID command argument
Moderate
CVE-2026-47242
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Moderate
CVE-2026-47240
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Improper neutralization of special elements used in a command ('command injection') in M365...
Moderate
Unreviewed
CVE-2026-42824
was published
Jun 5, 2026
A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file...
Moderate
Unreviewed
CVE-2026-10273
was published
Jun 1, 2026
GoClaw has a Command Injection issue
Moderate
CVE-2026-10219
was published
for
github.com/nextlevelbuilder/goclaw
(Go)
Jun 1, 2026
A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the...
Moderate
Unreviewed
CVE-2026-10214
was published
Jun 1, 2026
A security vulnerability has been detected in FoundDream miniclawd up to...
Moderate
Unreviewed
CVE-2026-9452
was published
May 26, 2026
A vulnerability was determined in NousResearch hermes-agent up to...
Moderate
Unreviewed
CVE-2026-9367
was published
May 26, 2026
Improper neutralization of special elements used in a command ('command injection') in M365...
Moderate
Unreviewed
CVE-2026-42827
was published
May 26, 2026
Insufficient Validation of Names During AXFR
Moderate
Unreviewed
CVE-2026-42000
was published
May 21, 2026
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization...
Moderate
Unreviewed
CVE-2026-35070
was published
May 20, 2026
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as ...
Moderate
Unreviewed
CVE-2026-45585
was published
May 20, 2026
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and...
Moderate
Unreviewed
CVE-2026-40135
was published
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API