GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
630 advisories
Filter by severity
Deserialization of Untrusted Data in Dubbo
Critical
CVE-2021-43297
was published
for
org.apache.dubbo:dubbo
(Maven)
Jan 12, 2022
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
High
CVE-2021-4118
was published
for
pytorch-lightning
(pip)
Jan 6, 2022
Deserialization of Untrusted Data in Codeigniter4
High
CVE-2022-21647
was published
for
codeigniter4/framework
(Composer)
Jan 6, 2022
Deserialization of Untrusted Data in rust-cpuid
Critical
CVE-2021-45687
was published
for
raw-cpuid
(Rust)
Jan 6, 2022
Deserialization of Untrusted Data in Apache Heron
High
CVE-2020-1964
was published
for
org.apache.heron:heron-simulator
(Maven)
Jan 6, 2022
AjaxNetProfessional deserializes arbitrary JavaScript objects
High
CVE-2021-43853
was published
for
AjaxNetProfessional
(NuGet)
Jan 6, 2022
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
Critical
GHSA-3qpm-h9ch-px3c
was published
for
org.powernukkit:powernukkit
(Maven)
Jan 6, 2022
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
High
GHSA-3w6p-8f82-gw8r
was published
for
ru.yandex.clickhouse:clickhouse-jdbc-bridge
(Maven)
Dec 17, 2021
Deserialization of Untrusted Data in logback
Moderate
CVE-2021-42550
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 17, 2021
Remote Code Execution in AjaxNetProfessional
Critical
CVE-2021-23758
was published
for
AjaxNetProfessional
(NuGet)
Dec 16, 2021
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
High
CVE-2021-4104
was published
for
log4j:log4j
(Maven)
Dec 14, 2021
Incomplete fix for Apache Log4j vulnerability
Critical
CVE-2021-45046
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 14, 2021
Deserialization of Untrusted Data in topthink/framework
Critical
CVE-2021-36564
was published
for
topthink/framework
(Composer)
Dec 10, 2021
Unsafe Deserialization that can Result in Code Execution
High
CVE-2020-36282
was published
for
com.rabbitmq.jms:rabbitmq-jms
(Maven)
Dec 10, 2021
Remote code injection in Log4j
Critical
CVE-2021-44228
was published
for
com.guicedee.services:log4j-core
(Maven)
Dec 10, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36189
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36187
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36188
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36183
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36184
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36180
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36181
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36185
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36179
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
ProTip!
Advisories are also available from the
GraphQL API