GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,844
Maven
5,000+
npm
4,470
NuGet
779
pip
4,231
Pub
12
RubyGems
974
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
253 advisories
Filter by severity
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-5498
was published
Jun 3, 2025
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8....
Moderate
Unreviewed
CVE-2025-5499
was published
Jun 3, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object...
Moderate
Unreviewed
CVE-2025-60216
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object...
Moderate
Unreviewed
CVE-2025-60215
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing...
Moderate
Unreviewed
CVE-2025-60210
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object...
Moderate
Unreviewed
CVE-2025-31634
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in WePlugins - WordPress Development Company WP...
Moderate
Unreviewed
CVE-2025-67535
was published
Dec 9, 2025
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows...
Moderate
Unreviewed
CVE-2025-66073
was published
Nov 21, 2025
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync...
Moderate
Unreviewed
CVE-2025-60221
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to...
Moderate
Unreviewed
CVE-2025-60224
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder...
Moderate
Unreviewed
CVE-2025-49380
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object...
Moderate
Unreviewed
CVE-2025-32283
was published
Oct 22, 2025
TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool
Moderate
CVE-2026-0859
was published
for
typo3/cms-core
(Composer)
Jan 13, 2026
Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
Moderate
CVE-2026-22187
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
The communication protocol used between the
server process and the service control had a flaw...
Moderate
Unreviewed
CVE-2025-30025
was published
Jul 11, 2025
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of...
Moderate
Unreviewed
CVE-2025-15375
was published
Dec 31, 2025
Genymobile/scrcpy versions up to and including 3.3.3 and prior to commit 3e40b24 contain a global...
Moderate
Unreviewed
CVE-2025-34449
was published
Dec 19, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
Duplicate Advisory: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
GHSA-93vm-mqpw-8wh3
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Nov 25, 2025
•
withdrawn
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Moderate
GHSA-c6m7-q6pr-c64r
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Next Server Actions Source Code Exposure
Moderate
GHSA-w37m-7fhw-fmv9
was published
for
next
(npm)
Dec 11, 2025
Source Code Exposure Vulnerability in React Server Components
Moderate
CVE-2025-55183
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical....
Moderate
Unreviewed
CVE-2025-5114
was published
May 23, 2025
ProTip!
Advisories are also available from the
GraphQL API