GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,002 advisories
Filter by severity
Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows...
Critical
Unreviewed
CVE-2025-60238
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase...
Critical
Unreviewed
CVE-2025-60232
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product...
High
Unreviewed
CVE-2025-62008
was published
Oct 22, 2025
Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle Deserialization
Moderate
GHSA-cq46-m9x9-j8w2
was published
for
scapy
(pip)
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows...
Critical
Unreviewed
CVE-2025-60226
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue...
Critical
Unreviewed
CVE-2025-62025
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows...
High
Unreviewed
CVE-2025-52740
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection...
High
Unreviewed
CVE-2025-60212
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection...
Critical
Unreviewed
CVE-2025-60039
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object...
Critical
Unreviewed
CVE-2025-60213
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows...
Critical
Unreviewed
CVE-2025-60214
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object...
Moderate
Unreviewed
CVE-2025-60216
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync...
Moderate
Unreviewed
CVE-2025-60221
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to...
Moderate
Unreviewed
CVE-2025-60224
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator...
High
Unreviewed
CVE-2025-52737
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder...
Moderate
Unreviewed
CVE-2025-49380
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For...
High
Unreviewed
CVE-2025-59007
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing...
Moderate
Unreviewed
CVE-2025-60210
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object...
Moderate
Unreviewed
CVE-2025-60215
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and...
High
Unreviewed
CVE-2025-60209
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object...
Moderate
Unreviewed
CVE-2025-31634
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object...
Moderate
Unreviewed
CVE-2025-32283
was published
Oct 22, 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Wazuh server vulnerable to remote code execution
Critical
CVE-2025-24016
was published
for
github.com/wazuh/wazuh
(Go)
Apr 22, 2025
Remote code injection in Log4j
Critical
CVE-2021-44228
was published
for
com.guicedee.services:log4j-core
(Maven)
Dec 10, 2021
ProTip!
Advisories are also available from the
GraphQL API