Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
actions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow
CVE-2026-34243
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
CVE-2026-33634
Trivy ecosystem supply chain was briefly compromised
Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow
CVE-2026-32947
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
CVE-2026-32946
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
CVE-2026-31976
xygeni-action v5 tag poisoned with C2 backdoor
CVE-2026-31900
Black's vulnerable version parsing leads to RCE in GitHub Action
CVE-2026-26189
Trivy Action has a script injection via sourced env file in composite action
CVE-2026-25761
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
CVE-2026-25598
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
j178/prek-action vulnerable to arbitrary code injection in composite action
CVE-2025-59844
Argument injection vulnerability in SonarQube Scan Action
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
CVE-2025-58178
Command Injection via sonarqube-scan-action GitHub Action
CVE-2024-48908
lychee link checking action affected by arbitrary code injection in composite action
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
CVE-2025-54416
tj-actions/branch-names has a Command Injection Vulnerability
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
Showing 1 - 20 of 1,000+ results