GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
Low
CVE-2026-35537
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
Low
CVE-2026-2970
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function
Low
CVE-2026-2898
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function...
Low
Unreviewed
CVE-2026-2555
was published
Feb 16, 2026
Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
Low
CVE-2026-24656
was published
for
org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket
(Maven)
Jan 26, 2026
Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux...
Low
Unreviewed
CVE-2025-69276
was published
Jan 12, 2026
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
Low
CVE-2025-50460
was published
for
ms-swift
(pip)
Jul 31, 2025
A potential security vulnerability has been identified in the Poly Clariti Manager for versions...
Low
Unreviewed
CVE-2025-43489
was published
Jul 23, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2025-32897
was published
for
org.apache.seata:seata-config-core
(Maven)
Jun 28, 2025
Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
Low
CVE-2025-6279
was published
for
upsonic
(pip)
Jun 19, 2025
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an...
Low
Unreviewed
CVE-2025-20276
was published
Jun 4, 2025
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java...
Low
Unreviewed
CVE-2025-30012
was published
May 13, 2025
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Low
Unreviewed
CVE-2023-35814
was published
Apr 28, 2025
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on...
Low
Unreviewed
CVE-2023-35815
was published
Apr 28, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2024-47552
was published
for
org.apache.seata:seata-config-core
(Maven)
Mar 20, 2025
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
shared_preferences_android vulnerability
Low
GHSA-3hpf-ff72-j67p
was published
for
shared_preferences_android
(Pub)
Dec 6, 2024
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected...
Low
Unreviewed
CVE-2024-10749
was published
Nov 4, 2024
Admidio Vulnerable to HTML Injection In The Messages Section
Low
CVE-2024-47836
was published
for
admidio/admidio
(Composer)
Oct 16, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21217
was published
Oct 15, 2024
Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before...
Low
Unreviewed
CVE-2023-26592
was published
Oct 10, 2024
OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies...
Low
Unreviewed
CVE-2024-34274
was published
May 21, 2024
Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization...
Low
Unreviewed
CVE-2024-22460
was published
May 8, 2024
ProTip!
Advisories are also available from the
GraphQL API