GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
827 advisories
Filter by severity
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
torch
(pip)
Apr 18, 2025
Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards allows Object...
Critical
Unreviewed
CVE-2025-39551
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity allows Object...
Critical
Unreviewed
CVE-2025-39550
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons...
Critical
Unreviewed
CVE-2025-39588
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in wpWax HelpGent allows Object Injection. This...
Critical
Unreviewed
CVE-2025-32658
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus allows Object...
Critical
Unreviewed
CVE-2025-32572
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider allows Object...
Critical
Unreviewed
CVE-2025-27286
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz allows Object Injection. This...
Critical
Unreviewed
CVE-2025-27287
was published
Apr 17, 2025
Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection....
Critical
Unreviewed
CVE-2025-30985
was published
Apr 15, 2025
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress...
Critical
Unreviewed
CVE-2025-3439
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly allows Object...
Critical
Unreviewed
CVE-2025-32607
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object...
Critical
Unreviewed
CVE-2025-32568
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table...
Critical
Unreviewed
CVE-2025-32569
was published
Apr 11, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-32375
was published
for
bentoml
(pip)
Apr 9, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of...
Critical
Unreviewed
CVE-2025-24447
was published
Apr 8, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender...
Critical
Unreviewed
CVE-2025-2244
was published
Apr 4, 2025
Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection....
Critical
Unreviewed
CVE-2025-31612
was published
Apr 1, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows...
Critical
Unreviewed
CVE-2025-31084
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing...
Critical
Unreviewed
CVE-2025-31087
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics...
Critical
Unreviewed
CVE-2025-22526
was published
Mar 28, 2025
Deserialization of Untrusted Data vulnerability in Shinetheme Traveler.This issue affects...
Critical
Unreviewed
CVE-2025-26873
was published
Mar 28, 2025
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP...
Critical
Unreviewed
CVE-2025-2332
was published
Mar 27, 2025
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when...
Critical
Unreviewed
CVE-2025-29310
was published
Mar 24, 2025
ProTip!
Advisories are also available from the
GraphQL API