GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,646 advisories
Filter by severity
A vulnerability allowing remote code execution (RCE) for domain users.
Critical
Unreviewed
CVE-2025-23120
was published
Mar 20, 2025
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2024-13921
was published
Mar 20, 2025
A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC...
Critical
Unreviewed
CVE-2024-12433
was published
Mar 20, 2025
A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The...
Critical
Unreviewed
CVE-2024-12044
was published
Mar 20, 2025
A pickle deserialization vulnerability exists in the Latex English error correction plug-in...
High
Unreviewed
CVE-2024-11039
was published
Mar 20, 2025
The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all...
Critical
Unreviewed
CVE-2024-13410
was published
Mar 19, 2025
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to...
High
Unreviewed
CVE-2024-49744
was published
Jan 22, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager...
High
Unreviewed
CVE-2025-26921
was published
Mar 16, 2025
Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
CVE-2025-2000
was published
for
qiskit
(pip)
Mar 14, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Duplicate Advisory: Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
GHSA-3pwp-2fqj-6g2p
was published
for
qiskit
(pip)
Mar 14, 2025
•
withdrawn
The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object...
Critical
Unreviewed
CVE-2024-13824
was published
Mar 14, 2025
Jenkins allows Execution of Code by Opening a JRMP Listener
Critical
CVE-2016-0788
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Jenkins allows Deserialization of Untrusted Data via an XML File
High
CVE-2016-0792
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be...
High
Unreviewed
CVE-2024-9005
was published
Oct 8, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21217
was published
Oct 15, 2024
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection...
High
Unreviewed
CVE-2024-10942
was published
Mar 13, 2025
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget...
High
Unreviewed
CVE-2024-2006
was published
Mar 13, 2024
VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of...
Critical
Unreviewed
CVE-2025-25940
was published
Mar 10, 2025
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is...
High
Unreviewed
CVE-2024-1859
was published
Mar 1, 2024
The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP...
High
Unreviewed
CVE-2024-0825
was published
Mar 5, 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because...
Critical
Unreviewed
CVE-2023-27372
was published
Feb 28, 2023
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
High
Unreviewed
CVE-2025-27925
was published
Mar 11, 2025
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting...
Critical
Unreviewed
CVE-2025-27816
was published
Mar 7, 2025
Microsoft Exchange Server Remote Code Execution Vulnerability.
High
Unreviewed
CVE-2022-41082
was published
Oct 4, 2022
ProTip!
Advisories are also available from the
GraphQL API