GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,006 advisories
Filter by severity
Deserialization of Untrusted Data in Beaker
Moderate
CVE-2013-7489
was published
for
Beaker
(pip)
May 5, 2022
Deserialization of Untrusted Data in Gson
High
CVE-2022-25647
was published
for
com.google.code.gson:gson
(Maven)
May 3, 2022
Remote Code Execution vulnerability in Jenkins Literate Plugin
High
CVE-2020-2158
was published
for
org.jenkins-ci.plugins:literate
(Maven)
May 24, 2022
Apache Dubbo vulnerable to remote code execution via Telnet Handler
Critical
CVE-2021-32824
was published
for
org.apache.dubbo:dubbo-parent
(Maven)
Jan 3, 2023
replicator vulnerable to Deserialization of Untrusted Data
Critical
CVE-2021-33420
was published
for
replicator
(npm)
Dec 15, 2022
A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The...
High
Unreviewed
CVE-2019-18283
was published
May 24, 2022
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3...
Moderate
Unreviewed
CVE-2019-18631
was published
May 24, 2022
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Critical
Unreviewed
CVE-2019-15780
was published
May 24, 2022
Code injection in Kubernetes Java Client
Moderate
CVE-2021-25738
was published
for
io.kubernetes:client-java
(Maven)
Oct 12, 2021
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
High
CVE-2020-2211
was published
for
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
(Maven)
May 24, 2022
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1...
High
Unreviewed
CVE-2019-10135
was published
May 24, 2022
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a...
Critical
Unreviewed
CVE-2022-24108
was published
May 18, 2022
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and...
High
Unreviewed
CVE-2022-1118
was published
May 18, 2022
** UNSUPPORTED WHEN ASSIGNED ** A remote insecure deserialization vulnerability exixsts in VMWare...
Critical
Unreviewed
CVE-2022-38652
was published
Nov 12, 2022
** UNSUPPORTED WHEN ASSIGNED ** A remote unauthenticated insecure deserialization vulnerability...
Critical
Unreviewed
CVE-2022-38650
was published
Nov 12, 2022
Deserialization of Untrusted Data in SinGooCMS.Utility
Critical
CVE-2022-0749
was published
for
SinGooCMS.Utility
(NuGet)
Mar 18, 2022
Deserialization of Untrusted Data in Apache Hadoop YARN
High
CVE-2021-25642
was published
for
org.apache.hadoop:hadoop-yarn-server
(Maven)
Aug 26, 2022
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6...
Critical
Unreviewed
CVE-2022-4120
was published
Dec 26, 2022
QOS.ch Logback vulnerable to Deserialization of Untrusted Data
Critical
CVE-2017-5929
was published
for
ch.qos.logback:logback-classic
(Maven)
Jun 7, 2021
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action...
High
Unreviewed
CVE-2019-9061
was published
May 13, 2022
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to...
High
Unreviewed
CVE-2019-9057
was published
May 13, 2022
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured...
Critical
Unreviewed
CVE-2016-6330
was published
May 17, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2022-35872
was published
Jul 26, 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an...
High
Unreviewed
CVE-2022-2903
was published
Sep 27, 2022
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior...
Critical
Unreviewed
CVE-2022-33318
was published
Jul 21, 2022
ProTip!
Advisories are also available from the
GraphQL API