GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,002 advisories
Filter by severity
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-62204
was published
Nov 11, 2025
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized...
Critical
Unreviewed
CVE-2025-59287
was published
Oct 14, 2025
Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets...
Critical
Unreviewed
CVE-2025-49393
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object...
Critical
Unreviewed
CVE-2025-53586
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection...
Critical
Unreviewed
CVE-2025-53242
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite...
Critical
Unreviewed
CVE-2025-48086
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve...
Critical
Unreviewed
CVE-2025-49386
was published
Nov 6, 2025
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is...
High
Unreviewed
CVE-2025-12099
was published
Nov 8, 2025
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-f83h-ghpp-7wcc
was published
for
pdfminer.six
(pip)
Nov 7, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
High
GHSA-wf5f-4jwr-ppcp
was published
for
pdfminer.six
(pip)
Nov 7, 2025
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress...
High
Unreviewed
CVE-2025-58592
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows...
High
Unreviewed
CVE-2025-58619
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from...
High
Unreviewed
CVE-2025-62035
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user...
Unknown
Unreviewed
CVE-2025-60245
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows...
Unknown
Unreviewed
CVE-2025-58998
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi...
High
Unreviewed
CVE-2025-54719
was published
Nov 6, 2025
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft...
Unknown
Unreviewed
CVE-2025-58636
was published
Nov 6, 2025
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-12305
was published
Oct 27, 2025
Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-54539
was published
for
Apache.NMS.AMQP
(NuGet)
Oct 16, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
Apache Seata: Deserialization of untrusted Data in Apache Seata Server
High
CVE-2025-53606
was published
for
org.apache.seata:seata-serializer-fury
(Maven)
Aug 8, 2025
ProTip!
Advisories are also available from the
GraphQL API