GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,002 advisories
Filter by severity
jsonpickle unsafe deserialization
Critical
CVE-2020-22083
was published
for
jsonpickle
(pip)
May 24, 2022
QuantConnect Lean vulnerable to insecure deserialization
Critical
CVE-2020-20136
was published
for
QuantConnect.Common
(NuGet)
May 24, 2022
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all...
High
Unreviewed
CVE-2020-9301
was published
May 24, 2022
, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. This CVE ID is unique from CVE...
High
Unreviewed
CVE-2020-17144
was published
May 24, 2022
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security...
Critical
Unreviewed
CVE-2020-27131
was published
May 24, 2022
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote...
Critical
Unreviewed
CVE-2020-5664
was published
May 24, 2022
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object...
High
Unreviewed
CVE-2020-28339
was published
May 24, 2022
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility...
Critical
Unreviewed
CVE-2020-28032
was published
May 24, 2022
fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution
High
CVE-2020-10721
was published
for
io.fabric8:fabric8-maven-plugin
(Maven)
May 24, 2022
A accessmgrservlet classname deserialization of untrusted data remote code execution...
Critical
Unreviewed
CVE-2020-24648
was published
May 24, 2022
A Remote Code Execution vulnerability exists in PcVue from version 8.10 onward, due to the unsafe...
Critical
Unreviewed
CVE-2020-26867
was published
May 24, 2022
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the...
High
Unreviewed
CVE-2020-4280
was published
May 24, 2022
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. It uses...
High
Unreviewed
CVE-2020-25258
was published
May 24, 2022
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. It...
High
Unreviewed
CVE-2020-25260
was published
May 24, 2022
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. It uses...
High
Unreviewed
CVE-2020-25259
was published
May 24, 2022
Maven Extension plugin for Gradle Enterprise vulnerable to Deserialization of Untrusted Data
High
CVE-2020-15777
was published
for
com.gradle:gradle-enterprise-maven-extension
(Maven)
May 24, 2022
Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by...
Moderate
Unreviewed
CVE-2020-10289
was published
May 24, 2022
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute...
High
Unreviewed
CVE-2020-4589
was published
May 24, 2022
Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability
High
CVE-2020-15842
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to achieve...
High
Unreviewed
CVE-2020-14172
was published
May 24, 2022
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
High
CVE-2020-2211
was published
for
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
(Maven)
May 24, 2022
Wildfly Unsafe Deserialization Vulnerability
High
CVE-2020-10740
was published
for
org.wildfly:wildfly-parent
(Maven)
May 24, 2022
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates...
High
Unreviewed
CVE-2020-14933
was published
May 24, 2022
Deserialization of Untrusted Data in Spring Batch
High
CVE-2020-5411
was published
for
org.springframework.batch:spring-batch-core
(Maven)
May 24, 2022
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due...
Low
Unreviewed
CVE-2020-0132
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API