GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,007 advisories
Filter by severity
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore...
Critical
Unreviewed
CVE-2024-33553
was published
Apr 29, 2024
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress...
High
Unreviewed
CVE-2024-13556
was published
Feb 18, 2025
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object...
High
Unreviewed
CVE-2020-28339
was published
May 24, 2022
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-1177
was published
Feb 11, 2025
The application deserializes untrusted data without sufficiently verifying that the resulting...
Critical
Unreviewed
CVE-2024-37361
was published
Feb 20, 2025
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Critical
Unreviewed
CVE-2024-13789
was published
Feb 20, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2024-28777
was published
Feb 19, 2025
Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
Critical
CVE-2024-56180
was published
for
org.apache.eventmesh:eventmesh-meta-raft
(Maven)
Feb 14, 2025
Payara Server allows remote attackers to load malicious code on the server once a JNDI directory scan is performed
Critical
CVE-2023-28462
was published
for
fish.payara.server:payara-aggregator
(Maven)
Mar 30, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2022-28685
was published
Mar 29, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2022-2561
was published
Mar 29, 2023
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
High
Unreviewed
CVE-2024-13636
was published
Feb 18, 2025
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
Critical
Unreviewed
CVE-2024-12562
was published
Feb 15, 2025
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11393
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11392
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11394
was published
for
transformers
(pip)
Nov 23, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High
CVE-2023-50943
was published
for
apache-airflow
(pip)
Jan 24, 2024
Apache IoTDB: Unsafe deserialize map in Sync Tool
Critical
CVE-2023-51656
was published
for
org.apache.iotdb:iotdb-parent
(Maven)
Dec 21, 2023
Apache InLong Manager Arbitrary File Read Vulnerability
High
CVE-2023-51785
was published
for
org.apache.inlong:manager-pojo
(Maven)
Jan 3, 2024
Bypass serialize checks in Apache Dubbo
Critical
CVE-2023-29234
was published
for
org.apache.dubbo:dubbo
(Maven)
Dec 15, 2023
Apache Dubbo: Bypass deny serialize list check in Apache Dubbo
Critical
CVE-2023-46279
was published
for
org.apache.dubbo:dubbo
(Maven)
Dec 15, 2023
Apache UIMA Java SDK Deserialization of Untrusted Data, Improper Input Validation vulnerability
High
CVE-2023-39913
was published
for
org.apache.uima:uimaj
(Maven)
Nov 8, 2023
Remote code execution in Apache Jackrabbit
Critical
CVE-2023-37895
was published
for
org.apache.jackrabbit:jackrabbit-standalone
(Maven)
Jul 25, 2023
JDBC URL bypassing by allowLoadLocalInfileInPath param
High
CVE-2023-34434
was published
for
org.apache.inlong:manager-pojo
(Maven)
Jul 25, 2023
Apache NiFi vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2023-34212
was published
for
org.apache.nifi:nifi-jms-processors
(Maven)
Jun 12, 2023
ProTip!
Advisories are also available from the
GraphQL API