GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,938 advisories
Filter by severity
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code...
Critical
Unreviewed
CVE-2025-58384
was published
Sep 26, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-49886
was published
Oct 6, 2025
Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on...
Critical
Unreviewed
CVE-2025-10363
was published
Oct 6, 2025
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
Moderate
CVE-2025-61765
was published
for
python-socketio
(pip)
Oct 7, 2025
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the ...
Moderate
Unreviewed
CVE-2025-60828
was published
Oct 8, 2025
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-60834
was published
Oct 8, 2025
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the...
Moderate
Unreviewed
CVE-2025-60830
was published
Oct 8, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The...
Moderate
Unreviewed
CVE-2025-61505
was published
Oct 10, 2025
Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to...
High
Unreviewed
CVE-2025-11622
was published
Oct 13, 2025
ProTip!
Advisories are also available from the
GraphQL API