GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
690 advisories
Filter by severity
Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection....
Critical
Unreviewed
CVE-2025-30985
was published
Apr 15, 2025
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress...
Critical
Unreviewed
CVE-2025-3439
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly allows Object...
Critical
Unreviewed
CVE-2025-32607
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object...
Critical
Unreviewed
CVE-2025-32568
was published
Apr 11, 2025
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn – WordPress Posts Table...
Critical
Unreviewed
CVE-2025-32569
was published
Apr 11, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-32375
was published
for
bentoml
(pip)
Apr 9, 2025
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Critical
CVE-2024-9052
was published
for
vllm
(pip)
Mar 20, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of...
Critical
Unreviewed
CVE-2025-24447
was published
Apr 8, 2025
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects...
Critical
Unreviewed
CVE-2024-30224
was published
Mar 28, 2024
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender...
Critical
Unreviewed
CVE-2025-2244
was published
Apr 4, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Withdrawn Advisory: PyTorch deserialization vulnerability
Critical
CVE-2024-7804
was published
for
torch
(pip)
Mar 20, 2025
•
withdrawn
Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection....
Critical
Unreviewed
CVE-2025-31612
was published
Apr 1, 2025
Deserialization of Untrusted Data and Code Injection in xstream
Critical
CVE-2019-10173
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jul 26, 2019
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows...
Critical
Unreviewed
CVE-2025-31084
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing...
Critical
Unreviewed
CVE-2025-31087
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics...
Critical
Unreviewed
CVE-2025-22526
was published
Mar 28, 2025
Deserialization of Untrusted Data vulnerability in Shinetheme Traveler.This issue affects...
Critical
Unreviewed
CVE-2025-26873
was published
Mar 28, 2025
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP...
Critical
Unreviewed
CVE-2025-2332
was published
Mar 27, 2025
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when...
Critical
Unreviewed
CVE-2025-29310
was published
Mar 24, 2025
vLLM Allows Remote Code Execution via Mooncake Integration
Critical
CVE-2025-29783
was published
for
vllm
(pip)
Mar 19, 2025
vLLM Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-11041
was published
for
vllm
(pip)
Mar 20, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-12029
was published
for
InvokeAI
(pip)
Mar 21, 2025
ProTip!
Advisories are also available from the
GraphQL API