GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
553 advisories
Filter by severity
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow...
Critical
Unreviewed
CVE-2019-18364
was published
May 24, 2022
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON...
Critical
Unreviewed
CVE-2019-12017
was published
May 24, 2022
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow...
Critical
Unreviewed
CVE-2019-12630
was published
May 24, 2022
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
Critical
Unreviewed
CVE-2019-16894
was published
May 24, 2022
A vulnerability was discovered in BMC MyIT Digital Workplace DWP before 18.11. The DWP component...
Critical
Unreviewed
CVE-2019-16755
was published
May 24, 2022
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is...
Critical
Unreviewed
CVE-2019-0189
was published
May 24, 2022
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Critical
Unreviewed
CVE-2018-20987
was published
May 24, 2022
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
Critical
Unreviewed
CVE-2018-20984
was published
May 24, 2022
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6...
Critical
Unreviewed
CVE-2019-0344
was published
May 24, 2022
Akamai CloudTest before 58.30 allows remote code execution.
Critical
Unreviewed
CVE-2019-11011
was published
May 24, 2022
In Godot through 3.1, remote code execution is possible due to the deserialization policy not...
Critical
Unreviewed
CVE-2019-10069
was published
May 24, 2022
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in...
Critical
Unreviewed
CVE-2019-9874
was published
May 24, 2022
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in...
Critical
Unreviewed
CVE-2019-6980
was published
May 24, 2022
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source...
Critical
Unreviewed
CVE-2019-12241
was published
May 24, 2022
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or...
Critical
Unreviewed
CVE-2019-12240
was published
May 24, 2022
An attacker could send a specifically crafted payload to the XML-RPC invocation script and...
Critical
Unreviewed
CVE-2019-5434
was published
May 24, 2022
eDeploy has RCE via cPickle deserialization of untrusted data
Critical
Unreviewed
CVE-2014-3699
was published
May 17, 2022
Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution...
Critical
Unreviewed
CVE-2023-51570
was published
Apr 2, 2024
** UNSUPPORTED WHEN ASSIGNED ** IBM InfoSphere Information Server 8.5.0.0 is affected by...
Critical
Unreviewed
CVE-2020-27583
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** A Java insecure deserialization vulnerability in Adobe LiveCycle...
Critical
Unreviewed
CVE-2023-28500
was published
Apr 6, 2023
Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue...
Critical
Unreviewed
CVE-2024-30228
was published
Mar 28, 2024
Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue...
Critical
Unreviewed
CVE-2024-30227
was published
Mar 28, 2024
Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects...
Critical
Unreviewed
CVE-2024-30225
was published
Mar 28, 2024
Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects...
Critical
Unreviewed
CVE-2024-30226
was published
Mar 28, 2024
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects...
Critical
Unreviewed
CVE-2024-30224
was published
Mar 28, 2024
ProTip!
Advisories are also available from the
GraphQL API