GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,007 advisories
Filter by severity
The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all...
Moderate
Unreviewed
CVE-2025-8871
was published
Nov 5, 2025
Apache Seata: Deserialization of untrusted Data in Apache Seata Server
High
CVE-2025-53606
was published
for
org.apache.seata:seata-serializer-fury
(Maven)
Aug 8, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-54539
was published
for
Apache.NMS.AMQP
(NuGet)
Oct 16, 2025
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-12305
was published
Oct 27, 2025
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
High
GHSA-wf5f-4jwr-ppcp
was published
for
pdfminer.six
(pip)
Nov 7, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-f83h-ghpp-7wcc
was published
for
pdfminer.six
(pip)
Nov 7, 2025
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is...
High
Unreviewed
CVE-2025-12099
was published
Nov 8, 2025
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized...
Critical
Unreviewed
CVE-2025-59287
was published
Oct 14, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-62204
was published
Nov 11, 2025
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
Critical
Unreviewed
CVE-2025-11367
was published
Nov 12, 2025
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5679
was published
Jun 5, 2025
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5680
was published
Jun 5, 2025
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could...
Critical
Unreviewed
CVE-2025-42944
was published
Sep 9, 2025
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is...
Moderate
Unreviewed
CVE-2025-63617
was published
Nov 10, 2025
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization...
High
Unreviewed
CVE-2025-12844
was published
Nov 13, 2025
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object...
Moderate
Unreviewed
CVE-2025-31634
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object...
Moderate
Unreviewed
CVE-2025-32283
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows...
High
Unreviewed
CVE-2025-52740
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For...
High
Unreviewed
CVE-2025-59007
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing...
Moderate
Unreviewed
CVE-2025-60210
was published
Oct 22, 2025
ProTip!
Advisories are also available from the
GraphQL API