GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,646 advisories
Filter by severity
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization...
Moderate
Unreviewed
CVE-2025-27130
was published
Apr 1, 2025
jooby-pac4j: deserialization of untrusted data
High
CVE-2025-31129
was published
for
io.jooby:jooby-pac4j
(Maven)
Apr 1, 2025
Deserialization of Untrusted Data and Code Injection in xstream
Critical
CVE-2019-10173
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jul 26, 2019
Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection....
Critical
Unreviewed
CVE-2025-31612
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object...
High
Unreviewed
CVE-2025-30892
was published
Apr 1, 2025
Withdrawn Advisory: PyTorch deserialization vulnerability
Critical
CVE-2024-7804
was published
for
torch
(pip)
Mar 20, 2025
•
withdrawn
Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue...
Moderate
Unreviewed
CVE-2024-32431
was published
Apr 15, 2024
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to...
High
Unreviewed
CVE-2003-0791
was published
Apr 29, 2022
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider allows Object...
High
Unreviewed
CVE-2025-30889
was published
Apr 3, 2025
The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is...
High
Unreviewed
CVE-2024-1772
was published
Mar 13, 2024
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender...
Critical
Unreviewed
CVE-2025-2244
was published
Apr 4, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common...
High
Unreviewed
CVE-2022-45923
was published
Jan 19, 2023
Deserialization mismatch vulnerability in the DSoftBus module
Impact: Successful exploitation of...
High
Unreviewed
CVE-2025-31175
was published
Apr 7, 2025
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the...
Moderate
Unreviewed
CVE-2025-2251
was published
Apr 7, 2025
Picklescan failed to detect to some unsafe global function in Numpy library
Moderate
GHSA-fj43-3qmq-673f
was published
for
picklescan
(pip)
Apr 7, 2025
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For...
High
Unreviewed
CVE-2024-30230
was published
Mar 28, 2024
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-29793
was published
Apr 8, 2025
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects...
Critical
Unreviewed
CVE-2024-30224
was published
Mar 28, 2024
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue...
Moderate
Unreviewed
CVE-2024-30221
was published
Mar 28, 2024
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of...
High
Unreviewed
CVE-2025-30285
was published
Apr 8, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of...
High
Unreviewed
CVE-2025-30284
was published
Apr 8, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of...
Critical
Unreviewed
CVE-2025-24447
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API