GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,006 advisories
Filter by severity
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 ...
High
Unreviewed
CVE-2025-40759
was published
Aug 12, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
High
Unreviewed
CVE-2024-54678
was published
Aug 12, 2025
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
High
GHSA-9gvj-pp9x-gcfr
was published
for
picklescan
(pip)
Aug 12, 2025
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via...
Critical
Unreviewed
CVE-2025-45146
was published
Aug 11, 2025
Liferay Portal Allows RCE via Deserialization of a JSON Payload
Critical
CVE-2019-16891
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2022
Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue...
Moderate
Unreviewed
CVE-2024-31308
was published
Apr 7, 2024
ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a...
Moderate
Unreviewed
CVE-2025-55136
was published
Aug 7, 2025
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54639
was published
Aug 6, 2025
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54640
was published
Aug 6, 2025
Issue of inconsistent read/write serialization in the ad module.
Impact: Successful exploitation...
Moderate
Unreviewed
CVE-2025-54638
was published
Aug 6, 2025
Deserialization vulnerability of untrusted data in the ability module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54620
was published
Aug 6, 2025
CVE-2025-49083 is a vulnerability in the management console
of Absolute Secure Access after...
High
Unreviewed
CVE-2025-49083
was published
Jul 31, 2025
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
Low
CVE-2025-50460
was published
for
ms-swift
(pip)
Jul 31, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-8227
was published
Jul 27, 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through...
Critical
Unreviewed
CVE-2025-50472
was published
Aug 1, 2025
MS SWIFT Deserialization RCE Vulnerability
Moderate
GHSA-r54c-2xmf-2cf3
was published
for
ms-swift
(pip)
Jul 31, 2025
Apache Avro Java SDK vulnerable to Improper Input Validation
High
CVE-2023-39410
was published
for
org.apache.avro:avro
(Maven)
Sep 29, 2023
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender...
Critical
Unreviewed
CVE-2025-2244
was published
Apr 4, 2025
LangChain pickle deserialization of untrusted data
High
CVE-2024-5998
was published
for
langchain-community
(pip)
Sep 17, 2024
Withdrawn: Fortra GoAnywhere MFT Deserialization of Untrusted Data vulnerability affects metasploit-framework
High
CVE-2023-0669
was published
for
metasploit-framework
(RubyGems)
Feb 6, 2023
•
withdrawn
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to...
High
Unreviewed
CVE-2025-53078
was published
Jul 29, 2025
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local...
High
Unreviewed
CVE-2025-26397
was published
Jul 25, 2025
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows...
Moderate
Unreviewed
CVE-2025-4393
was published
Jul 25, 2025
Reverb use after free vulnerability
Moderate
CVE-2024-8375
was published
for
dm-reverb
(pip)
Sep 19, 2024
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability,...
Critical
Unreviewed
CVE-2025-7916
was published
Jul 21, 2025
ProTip!
Advisories are also available from the
GraphQL API