Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,001 advisories

Loading
QuantConnect Lean vulnerable to insecure deserialization Critical
CVE-2020-20136 was published for QuantConnect.Common (NuGet) May 24, 2022
fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution High
CVE-2020-10721 was published for io.fabric8:fabric8-maven-plugin (Maven) May 24, 2022
oscerd
Credited to oscerd
A accessmgrservlet classname deserialization of untrusted data remote code execution... Critical Unreviewed
CVE-2020-24648 was published May 24, 2022
Maven Extension plugin for Gradle Enterprise vulnerable to Deserialization of Untrusted Data High
CVE-2020-15777 was published for com.gradle:gradle-enterprise-maven-extension (Maven) May 24, 2022
Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability High
CVE-2020-15842 was published for com.liferay.portal:release.dxp.bom (Maven) May 24, 2022
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin High
CVE-2020-2211 was published for com.elasticbox.jenkins-ci.plugins:kubernetes-ci (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Wildfly Unsafe Deserialization Vulnerability High
CVE-2020-10740 was published for org.wildfly:wildfly-parent (Maven) May 24, 2022
Deserialization of Untrusted Data in Spring Batch High
CVE-2020-5411 was published for org.springframework.batch:spring-batch-core (Maven) May 24, 2022
ProTip! Advisories are also available from the GraphQL API