Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,870 advisories

Loading
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps Low
GHSA-vxmw-7h4f-hqxh was published for pypa/gh-action-pypi-publish (GitHub Actions) Sep 4, 2025
woodruffw
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool High
CVE-2025-58358 was published for mcp-markdownify-server (npm) Sep 2, 2025
0xRoyR
Command Injection via sonarqube-scan-action GitHub Action High
CVE-2025-58178 was published for SonarSource/sonarqube-scan-action (GitHub Actions) Sep 2, 2025
Torbjorn-Svensson
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the... Moderate Unreviewed
CVE-2025-50755 was published Sep 2, 2025
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the... Moderate Unreviewed
CVE-2025-50757 was published Sep 2, 2025
ProTip! Advisories are also available from the GraphQL API