GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,007 advisories
Filter by severity
YAML deserialization can run untrusted code
Moderate
CVE-2021-39132
was published
for
org.rundeck:rundeck-core
(Maven)
Sep 1, 2021
Deserialization of Untrusted Data in Apache Camel RabbitMQ
High
CVE-2020-11972
was published
for
org.apache.camel:camel-rabbitmq
(Maven)
May 21, 2021
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed...
Critical
Unreviewed
CVE-2018-20718
was published
May 13, 2022
Deserializer tampering in Apache Dubbo
Critical
CVE-2021-25641
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
Deserialization of Untrusted Data in Apache jUDDI
Critical
CVE-2021-37578
was published
for
org.apache.juddi:juddi-core
(Maven)
Aug 9, 2021
Deserialization of Untrusted Data in msgpack
Critical
CVE-2021-23410
was published
for
msgpack
(npm)
Jul 26, 2021
•
withdrawn
Remote Code Execution Vulnerability in Session Storage
Critical
CVE-2021-29485
was published
for
io.ratpack:ratpack-core
(Maven)
Jul 1, 2021
A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus'...
High
Unreviewed
CVE-2018-18589
was published
May 13, 2022
Deserialization of Untrusted Data in Apache Dubbo
Critical
CVE-2021-30179
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
Deserialization of Untrusted Data in Apache Heron
High
CVE-2020-1964
was published
for
org.apache.heron:heron-simulator
(Maven)
Jan 6, 2022
Insecure deserialization in Wire
Critical
CVE-2021-29508
was published
for
Wire
(NuGet)
May 19, 2021
Gadget chain attack in Nippy
High
CVE-2020-24164
was published
for
com.taoensso:nippy
(Maven)
Feb 10, 2022
Insecure Deserialization of untrusted data in rmccue/requests
Critical
CVE-2021-29476
was published
for
rmccue/requests
(Composer)
Apr 29, 2021
Deserialization of Untrusted Data in Apache ShardingSphere
High
CVE-2020-1947
was published
for
org.apache.shardingsphere:shardingsphere
(Maven)
Feb 10, 2022
"Deserialization errors in MyBatis"
High
CVE-2020-26945
was published
for
org.mybatis:mybatis
(Maven)
Apr 22, 2021
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize...
High
Unreviewed
CVE-2018-15576
was published
May 13, 2022
CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call...
Critical
Unreviewed
CVE-2018-10085
was published
May 13, 2022
Deserialization of Untrusted Data in Apache Dubbo
Critical
CVE-2020-1948
was published
for
org.apache.dubbo:dubbo
(Maven)
Feb 10, 2022
Fixes a bug in Zend Framework's Stream HTTP Wrapper
Critical
CVE-2021-21426
was published
for
openmage/magento-lts
(Composer)
Apr 22, 2021
Remote code execution in Apache Tapestry
Critical
CVE-2021-27850
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Jun 16, 2021
YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in...
Critical
Unreviewed
CVE-2018-1000641
was published
May 13, 2022
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14...
Critical
Unreviewed
CVE-2018-15959
was published
May 13, 2022
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form...
Critical
Unreviewed
CVE-2018-1000059
was published
May 13, 2022
openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request...
Critical
Unreviewed
CVE-2018-1000525
was published
May 13, 2022
** DISPUTED ** The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2...
High
Unreviewed
CVE-2017-8804
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API