GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
215 advisories
Filter by severity
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The...
Moderate
Unreviewed
CVE-2025-61505
was published
Oct 10, 2025
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the...
Moderate
Unreviewed
CVE-2025-60830
was published
Oct 8, 2025
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-60834
was published
Oct 8, 2025
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the ...
Moderate
Unreviewed
CVE-2025-60828
was published
Oct 8, 2025
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
Moderate
CVE-2025-61765
was published
for
python-socketio
(pip)
Oct 7, 2025
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-10770
was published
Sep 22, 2025
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-10771
was published
Sep 22, 2025
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10769
was published
Sep 22, 2025
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function...
Moderate
Unreviewed
CVE-2025-10768
was published
Sep 22, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
Moderate
Unreviewed
CVE-2025-9260
was published
Sep 3, 2025
Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg allows Object...
Moderate
Unreviewed
CVE-2025-54053
was published
Aug 20, 2025
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an...
Moderate
Unreviewed
CVE-2025-2180
was published
Aug 13, 2025
ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a...
Moderate
Unreviewed
CVE-2025-55136
was published
Aug 7, 2025
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54639
was published
Aug 6, 2025
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54640
was published
Aug 6, 2025
Issue of inconsistent read/write serialization in the ad module.
Impact: Successful exploitation...
Moderate
Unreviewed
CVE-2025-54638
was published
Aug 6, 2025
Deserialization vulnerability of untrusted data in the ability module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54620
was published
Aug 6, 2025
MS SWIFT Deserialization RCE Vulnerability
Moderate
GHSA-r54c-2xmf-2cf3
was published
for
ms-swift
(pip)
Jul 31, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-8227
was published
Jul 27, 2025
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows...
Moderate
Unreviewed
CVE-2025-4393
was published
Jul 25, 2025
A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This...
Moderate
Unreviewed
CVE-2025-7876
was published
Jul 20, 2025
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2025-30761
was published
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API