GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,801
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,010
NuGet
720
pip
3,810
Pub
12
RubyGems
930
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
521 advisories
Filter by severity
The communication protocol used between client and server had a flaw that could lead to an...
Critical
Unreviewed
CVE-2025-30023
was published
Jul 11, 2025
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of...
Critical
Unreviewed
CVE-2025-49533
was published
Jul 9, 2025
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data...
Critical
Unreviewed
CVE-2025-27203
was published
Jul 9, 2025
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can...
Critical
Unreviewed
CVE-2025-42980
was published
Jul 8, 2025
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables...
Critical
Unreviewed
CVE-2025-42963
was published
Jul 8, 2025
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload...
Critical
Unreviewed
CVE-2025-42964
was published
Jul 8, 2025
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative...
Critical
Unreviewed
CVE-2025-42966
was published
Jul 8, 2025
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution...
Critical
Unreviewed
CVE-2025-6810
was published
Jul 7, 2025
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code...
Critical
Unreviewed
CVE-2025-6811
was published
Jul 7, 2025
Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi...
Critical
Unreviewed
CVE-2025-49417
was published
Jul 4, 2025
An unauthenticated remote command execution vulnerability exists in the applyCT component of the...
Critical
Unreviewed
CVE-2025-34067
was published
Jul 2, 2025
The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to,...
Critical
Unreviewed
CVE-2024-13786
was published
Jul 2, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms allows Object...
Critical
Unreviewed
CVE-2025-52709
was published
Jun 27, 2025
Deserialization of Untrusted Data vulnerability in pebas CouponXxL allows Object Injection. This...
Critical
Unreviewed
CVE-2025-52725
was published
Jun 27, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk allows Object Injection....
Critical
Unreviewed
CVE-2025-52724
was published
Jun 27, 2025
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic allows Object...
Critical
Unreviewed
CVE-2025-28970
was published
Jun 27, 2025
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2025-36038
was published
Jun 26, 2025
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability....
Critical
Unreviewed
CVE-2025-2566
was published
Jun 24, 2025
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5...
Critical
Unreviewed
CVE-2025-25034
was published
Jun 20, 2025
Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and...
Critical
Unreviewed
CVE-2025-49330
was published
Jun 17, 2025
Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This...
Critical
Unreviewed
CVE-2025-31919
was published
Jun 17, 2025
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce...
Critical
Unreviewed
CVE-2025-30618
was published
Jun 17, 2025
Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay allows Object Injection...
Critical
Unreviewed
CVE-2025-49507
was published
Jun 10, 2025
Deserialization of Untrusted Data vulnerability in LoftOcean TinySalt allows Object Injection...
Critical
Unreviewed
CVE-2025-49455
was published
Jun 10, 2025
Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page...
Critical
Unreviewed
CVE-2025-31052
was published
Jun 9, 2025
ProTip!
Advisories are also available from the
GraphQL API