GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,007 advisories
Filter by severity
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability...
High
Unreviewed
CVE-2022-36958
was published
Oct 21, 2022
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability...
High
Unreviewed
CVE-2022-36957
was published
Oct 21, 2022
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability...
High
Unreviewed
CVE-2022-38108
was published
Oct 21, 2022
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2022-23734
was published
Oct 19, 2022
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the...
Critical
Unreviewed
CVE-2022-43019
was published
Oct 19, 2022
Hessian Lite for Apache Dubbo deserialization vulnerability
Critical
CVE-2022-39198
was published
for
com.alibaba:hessian-lite
(Maven)
Oct 19, 2022
MySQL JDBC deserialization vulnerability
Critical
CVE-2022-39312
was published
for
io.dataease:dataease-plugin-common
(Maven)
Oct 18, 2022
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS...
High
Unreviewed
CVE-2022-22241
was published
Oct 18, 2022
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
Critical
Unreviewed
CVE-2022-40889
was published
Oct 18, 2022
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15...
Moderate
Unreviewed
CVE-2022-3291
was published
Oct 17, 2022
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
Critical
Unreviewed
CVE-2018-18446
was published
Oct 13, 2022
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
Critical
Unreviewed
CVE-2018-18447
was published
Oct 13, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
High
CVE-2022-39297
was published
for
melisplatform/melis-cms
(Composer)
Oct 11, 2022
melisplatform/melis-front vulnerable to deserialization of untrusted data
High
CVE-2022-39298
was published
for
melisplatform/melis-front
(Composer)
Oct 11, 2022
In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could...
High
Unreviewed
CVE-2022-26472
was published
Oct 8, 2022
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services...
Critical
Unreviewed
CVE-2022-31680
was published
Oct 8, 2022
In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This...
High
Unreviewed
CVE-2022-26471
was published
Oct 8, 2022
TCPDF vulnerable to attackers triggering deserialization of arbitrary data
Critical
CVE-2018-17057
was published
for
fooman/tcpdf
(Composer)
Oct 6, 2022
Microsoft Exchange Server Remote Code Execution Vulnerability.
High
Unreviewed
CVE-2022-41082
was published
Oct 4, 2022
Uncontrolled Resource Consumption in FasterXML jackson-databind
High
CVE-2022-42004
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Oct 3, 2022
Uncontrolled Resource Consumption in Jackson-databind
High
CVE-2022-42003
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Oct 3, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
Critical
CVE-2022-39256
was published
for
CompositeC1.Core
(NuGet)
Sep 30, 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an...
High
Unreviewed
CVE-2022-2903
was published
Sep 27, 2022
Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
Critical
CVE-2022-36944
was published
for
org.scala-lang:scala-library
(Maven)
Sep 25, 2022
RCE vulnerability in Jenkins DotCi Plugin
High
CVE-2022-41237
was published
for
com.groupon.jenkins-ci.plugins:DotCi
(Maven)
Sep 22, 2022
ProTip!
Advisories are also available from the
GraphQL API