GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,262
NuGet
760
pip
4,058
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,006 advisories
Filter by severity
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy...
Critical
Unreviewed
CVE-2025-26399
was published
Sep 23, 2025
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object...
High
Unreviewed
CVE-2025-58662
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for...
High
Unreviewed
CVE-2025-57919
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector allows Object...
High
Unreviewed
CVE-2025-53465
was published
Sep 22, 2025
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-10770
was published
Sep 22, 2025
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-10771
was published
Sep 22, 2025
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10769
was published
Sep 22, 2025
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function...
Moderate
Unreviewed
CVE-2025-10768
was published
Sep 22, 2025
H2O affected by a deserialization vulnerability
Critical
CVE-2025-6544
was published
for
ai.h2o:h2o-core
(Maven)
Sep 22, 2025
Keras is vulnerable to Deserialization of Untrusted Data
High
CVE-2025-9906
was published
for
keras
(pip)
Sep 19, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling...
High
Unreviewed
CVE-2025-10492
was published
Sep 16, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
Monai: Unsafe use of Pickle deserialization may lead to RCE
High
CVE-2025-58757
was published
for
monai
(pip)
Sep 9, 2025
MONAI: Unsafe torch usage may lead to arbitrary code execution
High
CVE-2025-58756
was published
for
monai
(pip)
Sep 9, 2025
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an...
Critical
Unreviewed
CVE-2025-55232
was published
Sep 9, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-54897
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects...
Critical
Unreviewed
CVE-2025-47579
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress...
High
Unreviewed
CVE-2025-48101
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core allows Object...
High
Unreviewed
CVE-2025-53303
was published
Sep 9, 2025
An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a...
High
Unreviewed
CVE-2025-41701
was published
Sep 9, 2025
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could...
Critical
Unreviewed
CVE-2025-42944
was published
Sep 9, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API