GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,807
Erlang
36
GitHub Actions
31
Go
2,390
Maven
5,000+
npm
4,026
NuGet
720
pip
3,815
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
595 advisories
Filter by severity
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Apache Ignite: Possible RCE when deserializing incoming messages by the server node
Critical
CVE-2024-52577
was published
for
org.apache.ignite:ignite-core
(Maven)
Feb 14, 2025
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Critical
CVE-2024-47561
was published
for
org.apache.avro:avro
(Maven)
Oct 3, 2024
Deserialization of Untrusted Data in Log4j 1.x
High
CVE-2022-23302
was published
for
log4j:log4j
(Maven)
Jan 21, 2022
Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
Low
CVE-2025-6279
was published
for
upsonic
(pip)
Jun 19, 2025
Apache Kafka Connect vulnerable to Deserialization of Untrusted Data
High
CVE-2023-25194
was published
for
org.apache.kafka:connect
(Maven)
Feb 7, 2023
vLLM Allows Remote Code Execution via Mooncake Integration
Critical
CVE-2025-29783
was published
for
vllm
(pip)
Mar 19, 2025
akka-cluster-metrics uses Java serialization for cluster metrics
Moderate
CVE-2025-53393
was published
for
com.typesafe.akka:akka-cluster-metrics_2.13
(Maven)
Jun 29, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Critical
CVE-2025-32897
was published
for
org.apache.seata:seata-config-core
(Maven)
Jun 28, 2025
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
High
CVE-2025-24357
was published
for
vllm
(pip)
Jan 27, 2025
LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
Moderate
CVE-2025-46567
was published
for
llamafactory
(pip)
Apr 23, 2025
PowSyBl Core allows deserialization of untrusted SparseMatrix data
High
CVE-2025-47771
was published
for
com.powsybl:powsybl-math
(Maven)
Jun 19, 2025
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization
Critical
CVE-2025-49113
was published
for
roundcube/roundcubemail
(Composer)
Jun 2, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27818
was published
for
org.apache.kafka:kafka
(Maven)
Jun 10, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27819
was published
for
org.apache.kafka:kafka
(Maven)
Jun 10, 2025
Apache InLong Deserialization of Untrusted Data Vulnerability
High
CVE-2025-27531
was published
for
org.apache.inlong:inlong-manager
(Maven)
Jun 6, 2025
HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-5173
was published
for
label-studio-ml
(pip)
May 26, 2025
laravel-auth0 SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-c42h-56wx-h85q
was published
for
auth0/login
(Composer)
Jun 6, 2025
Auth0 Symfony SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-98j6-67v3-mw34
was published
for
auth0/symfony
(Composer)
Jun 6, 2025
Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted Data
Critical
GHSA-862m-5253-832r
was published
for
auth0/wordpress
(Composer)
Jun 5, 2025
Auth0-PHP SDK Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-48951
was published
for
auth0/auth0-php
(Composer)
Jun 4, 2025
pypickle unsafe deserialization vulnerability
Moderate
CVE-2025-5174
was published
for
pypickle
(pip)
May 26, 2025
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55638
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API