GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,222
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,937 advisories
Filter by severity
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The...
Moderate
Unreviewed
CVE-2025-61505
was published
Oct 10, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-60834
was published
Oct 8, 2025
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the...
Moderate
Unreviewed
CVE-2025-60830
was published
Oct 8, 2025
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the ...
Moderate
Unreviewed
CVE-2025-60828
was published
Oct 8, 2025
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
Moderate
CVE-2025-61765
was published
for
python-socketio
(pip)
Oct 7, 2025
Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on...
Critical
Unreviewed
CVE-2025-10363
was published
Oct 6, 2025
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-49886
was published
Oct 6, 2025
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code...
Critical
Unreviewed
CVE-2025-58384
was published
Sep 26, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy...
Critical
Unreviewed
CVE-2025-26399
was published
Sep 23, 2025
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object...
High
Unreviewed
CVE-2025-58662
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector allows Object...
High
Unreviewed
CVE-2025-53465
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for...
High
Unreviewed
CVE-2025-57919
was published
Sep 22, 2025
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-10770
was published
Sep 22, 2025
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-10771
was published
Sep 22, 2025
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10769
was published
Sep 22, 2025
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function...
Moderate
Unreviewed
CVE-2025-10768
was published
Sep 22, 2025
H2O affected by a deserialization vulnerability
Critical
CVE-2025-6544
was published
for
ai.h2o:h2o-core
(Maven)
Sep 22, 2025
Keras is vulnerable to Deserialization of Untrusted Data
High
CVE-2025-9906
was published
for
keras
(pip)
Sep 19, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling...
High
Unreviewed
CVE-2025-10492
was published
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API