GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,634
NuGet
638
pip
3,249
Pub
10
RubyGems
867
Rust
819
Swift
35
Unreviewed advisories
All unreviewed
5,000+
189 advisories
Filter by severity
Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify...
Moderate
Unreviewed
CVE-2005-4699
was published
May 1, 2022
Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers...
Moderate
Unreviewed
CVE-2006-2057
was published
May 1, 2022
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier...
High
Unreviewed
CVE-2004-0489
was published
Apr 29, 2022
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to...
High
Unreviewed
CVE-2004-0480
was published
Apr 29, 2022
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0,...
High
Unreviewed
CVE-2001-0667
was published
Apr 30, 2022
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are...
Moderate
Unreviewed
CVE-2001-0150
was published
Apr 30, 2022
Some implementations of rlogin allow root access if given a -froot parameter.
High
Unreviewed
CVE-1999-0113
was published
Apr 30, 2022
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual...
Moderate
Unreviewed
CVE-2024-20287
was published
Jan 17, 2024
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved...
Moderate
Unreviewed
CVE-2023-20260
was published
Jan 17, 2024
Argument injection in a MimeTypeGuesser in Symfony
High
CVE-2019-18888
was published
for
symfony/http-foundation
(Composer)
Dec 2, 2019
Code execution in Embedchain
Critical
CVE-2024-23731
was published
for
embedchain
(pip)
Jan 21, 2024
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation...
High
Unreviewed
CVE-2023-20224
was published
Aug 17, 2023
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
High
CVE-2021-29472
was published
for
composer/composer
(Composer)
Apr 29, 2021
Missing input validation can lead to command execution in composer
High
CVE-2022-24828
was published
for
composer/composer
(Composer)
Apr 22, 2022
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments....
High
Unreviewed
CVE-2023-47804
was published
Dec 29, 2023
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2023-46681
was published
Dec 26, 2023
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software...
Moderate
Unreviewed
CVE-2023-6792
was published
Dec 13, 2023
An argument injection vulnerability has been identified in the
administrative web interface of...
Critical
Unreviewed
CVE-2023-6269
was published
Dec 5, 2023
A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root...
Moderate
Unreviewed
CVE-2022-37705
was published
Apr 16, 2023
Prototype Pollution in mixin-deep
Critical
CVE-2019-10746
was published
for
mixin-deep
(npm)
Aug 27, 2019
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29405
was published
Jun 8, 2023
Apache Airflow ODBC Provider Argument Injection vulnerability
High
CVE-2023-34395
was published
for
apache-airflow-providers-odbc
(pip)
Jun 27, 2023
blamer vulnerable to Arbitrary Argument Injection via the blameByFile() API
Moderate
CVE-2023-26143
was published
for
blamer
(npm)
Sep 19, 2023
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2022-20930
was published
Oct 1, 2022
Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile.
Moderate
CVE-2021-43809
was published
for
bundler
(RubyGems)
Dec 8, 2021
ProTip!
Advisories are also available from the
GraphQL API