GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
808 advisories
Filter by severity
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP...
High
Unreviewed
CVE-2025-0724
was published
Mar 22, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
CVE-2025-30160
was published
for
redlib
(Rust)
Mar 21, 2025
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2024-13921
was published
Mar 20, 2025
A pickle deserialization vulnerability exists in the Latex English error correction plug-in...
High
Unreviewed
CVE-2024-11039
was published
Mar 20, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager...
High
Unreviewed
CVE-2025-26921
was published
Mar 16, 2025
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection...
High
Unreviewed
CVE-2024-10942
was published
Mar 13, 2025
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
High
Unreviewed
CVE-2025-27925
was published
Mar 11, 2025
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for...
High
Unreviewed
CVE-2024-13906
was published
Mar 7, 2025
A deserialization of untrusted data vulnerability exists in NI G Web Development Software that...
High
Unreviewed
CVE-2024-12742
was published
Mar 6, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13777
was published
Mar 5, 2025
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection...
High
Unreviewed
CVE-2025-26999
was published
Mar 3, 2025
Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection....
High
Unreviewed
CVE-2025-26885
was published
Mar 3, 2025
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory...
High
Unreviewed
CVE-2025-26967
was published
Mar 3, 2025
Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk...
High
Unreviewed
CVE-2024-47092
was published
Mar 3, 2025
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection...
High
Unreviewed
CVE-2024-13833
was published
Mar 1, 2025
The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all...
High
Unreviewed
CVE-2024-13831
was published
Feb 28, 2025
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager...
High
Unreviewed
CVE-2025-27301
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This...
High
Unreviewed
CVE-2025-27300
was published
Feb 24, 2025
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
High
Unreviewed
CVE-2024-13899
was published
Feb 22, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an...
High
Unreviewed
CVE-2024-45084
was published
Feb 19, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2024-28777
was published
Feb 19, 2025
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
High
Unreviewed
CVE-2024-13636
was published
Feb 18, 2025
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress...
High
Unreviewed
CVE-2024-13556
was published
Feb 18, 2025
ProTip!
Advisories are also available from the
GraphQL API