GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,766 advisories
Filter by severity
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender...
Critical
Unreviewed
CVE-2025-2244
was published
Apr 4, 2025
LMDeploy Improper Input Validation Vulnerability
Moderate
CVE-2025-3162
was published
for
lmdeploy
(pip)
Apr 3, 2025
Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider allows Object...
High
Unreviewed
CVE-2025-30889
was published
Apr 3, 2025
Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection....
Critical
Unreviewed
CVE-2025-31612
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object...
High
Unreviewed
CVE-2025-30892
was published
Apr 1, 2025
jooby-pac4j: deserialization of untrusted data
High
CVE-2025-31129
was published
for
io.jooby:jooby-pac4j
(Maven)
Apr 1, 2025
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization...
Moderate
Unreviewed
CVE-2025-27130
was published
Apr 1, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object...
High
Unreviewed
CVE-2025-31074
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows...
Critical
Unreviewed
CVE-2025-31084
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing...
Critical
Unreviewed
CVE-2025-31087
was published
Apr 1, 2025
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted...
High
Unreviewed
CVE-2025-31103
was published
Mar 31, 2025
Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics...
Critical
Unreviewed
CVE-2025-22526
was published
Mar 28, 2025
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-2485
was published
Mar 28, 2025
Deserialization of Untrusted Data vulnerability in Shinetheme Traveler.This issue affects...
Critical
Unreviewed
CVE-2025-26873
was published
Mar 28, 2025
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7....
Moderate
Unreviewed
CVE-2025-2855
was published
Mar 27, 2025
Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress allows Object...
High
Unreviewed
CVE-2025-30773
was published
Mar 27, 2025
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP...
Critical
Unreviewed
CVE-2025-2332
was published
Mar 27, 2025
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress...
High
Unreviewed
CVE-2025-1913
was published
Mar 26, 2025
The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2024-13889
was published
Mar 26, 2025
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when...
Critical
Unreviewed
CVE-2025-29310
was published
Mar 24, 2025
yiisoft Yii2 Deserialization of Untrusted Data
Moderate
CVE-2025-2689
was published
for
yiisoft/yii2-dev
(Composer)
Mar 24, 2025
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This...
Moderate
Unreviewed
CVE-2025-2690
was published
Mar 24, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2025-1971
was published
Mar 22, 2025
ProTip!
Advisories are also available from the
GraphQL API