GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,844
Maven
5,000+
npm
4,470
NuGet
779
pip
4,231
Pub
12
RubyGems
974
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
2,140 advisories
Filter by severity
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code...
Critical
Unreviewed
CVE-2025-56005
was published
Jan 20, 2026
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2026-0726
was published
Jan 20, 2026
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in...
Critical
Unreviewed
CVE-2023-7334
was published
Jan 16, 2026
TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool
Moderate
CVE-2026-0859
was published
for
typo3/cms-core
(Composer)
Jan 13, 2026
Azure Core is vulnerable to deserialization of untrusted data
High
CVE-2026-21226
was published
for
azure-core
(pip)
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
Critical
CVE-2025-68924
was published
for
UmbracoForms
(NuGet)
Jan 13, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-20963
was published
Jan 13, 2026
LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe...
High
Unreviewed
CVE-2024-14021
was published
Jan 13, 2026
Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux...
Low
Unreviewed
CVE-2025-69276
was published
Jan 12, 2026
Fickling vulnerable to detection bypass due to "builtins" blindness
High
CVE-2026-22612
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
High
CVE-2026-22609
was published
for
fickling
(pip)
Jan 9, 2026
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
High
CVE-2026-22608
was published
for
fickling
(pip)
Jan 9, 2026
Fickling Blocklist Bypass: cProfile.run()
High
CVE-2026-22607
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has a bypass via runpy.run_path() and runpy.run_module()
High
CVE-2026-22606
was published
for
fickling
(pip)
Jan 9, 2026
vLLM introduced enhanced protection for CVE-2025-62164
High
GHSA-mcmc-2m55-j8jj
was published
for
vllm
(pip)
Jan 8, 2026
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters...
Critical
Unreviewed
CVE-2025-67911
was published
Jan 8, 2026
Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
Moderate
CVE-2026-22187
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows...
Critical
Unreviewed
CVE-2025-47552
was published
Jan 7, 2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows...
High
Unreviewed
CVE-2025-47553
was published
Jan 6, 2026
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection...
High
Unreviewed
CVE-2025-31047
was published
Jan 5, 2026
Feast vulnerable to Deserialization of Untrusted Data
High
CVE-2025-11157
was published
for
feast
(pip)
Jan 1, 2026
FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-15276
was published
Dec 31, 2025
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of...
Moderate
Unreviewed
CVE-2025-15375
was published
Dec 31, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
ProTip!
Advisories are also available from the
GraphQL API