GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,518
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,758
Pub
13
RubyGems
1,036
Rust
1,228
Swift
53
Unreviewed advisories
All unreviewed
5,000+
151 advisories
Filter by severity
MCP Server Kubernetes has an Argument Injection in port_forward tool via space-splitting
High
CVE-2026-39884
was published
for
mcp-server-kubernetes
(npm)
Apr 14, 2026
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh
High
GHSA-p4h8-56qp-hpgv
was published
for
@aiondadotcom/mcp-ssh
(npm)
Apr 14, 2026
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
High
CVE-2026-40113
was published
for
PraisonAI
(pip)
Apr 10, 2026
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and...
High
Unreviewed
CVE-2023-6634
was published
Jan 11, 2024
File Browser has a Command Injection via Hook Runner
High
CVE-2026-35585
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
High
CVE-2026-34769
was published
for
electron
(npm)
Apr 3, 2026
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to...
High
Unreviewed
CVE-2026-0634
was published
Apr 2, 2026
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF...
High
Unreviewed
CVE-2026-29954
was published
Mar 30, 2026
A remote, unauthenticated attacker may be able to send crafted messages
to the web server of the...
High
Unreviewed
CVE-2024-22182
was published
Mar 1, 2024
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters...
High
Unreviewed
CVE-2004-0411
was published
Apr 29, 2022
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter...
High
Unreviewed
CVE-2004-0121
was published
Apr 29, 2022
OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments
High
CVE-2026-22168
was published
for
openclaw
(npm)
Mar 2, 2026
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary...
High
Unreviewed
CVE-2006-1865
was published
May 1, 2022
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or...
High
Unreviewed
CVE-2006-3015
was published
May 1, 2022
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can...
High
Unreviewed
CVE-2025-41761
was published
Mar 9, 2026
The Settings application has an argument injection vulnerability. Successful exploitation of this...
High
Unreviewed
CVE-2022-37005
was published
Aug 11, 2022
OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes
High
CVE-2026-28470
was published
for
openclaw
(npm)
Feb 17, 2026
Gogs: Release tag option injection in release deletion
High
CVE-2026-26194
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute...
High
Unreviewed
CVE-2026-26514
was published
Mar 4, 2026
WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2026-0774
was published
Jan 23, 2026
A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity...
High
Unreviewed
CVE-2025-67858
was published
Jan 8, 2026
Easywall 0.3.1 allows authenticated remote command execution via a command injection...
High
Unreviewed
CVE-2024-58275
was published
Dec 4, 2025
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
High
CVE-2025-12613
was published
for
cloudinary
(npm)
Nov 10, 2025
An argument injection vulnerability exists in the affected product that could allow an attacker...
High
Unreviewed
CVE-2025-12556
was published
Nov 6, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
ProTip!
Advisories are also available from the
GraphQL API