GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
213 advisories
Filter by severity
Deserialization of Untrusted Data in Jython
Critical
CVE-2016-4000
was published
for
org.python:jython
(Maven)
May 13, 2022
Deserialization of Untrusted Data in Groovy
Critical
CVE-2016-6814
was published
for
org.codehaus.groovy:groovy
(Maven)
May 13, 2022
Apache MyFaces Trinidad Deserialization Vulnerability
Critical
CVE-2016-5019
was published
for
org.apache.myfaces.trinidad:trinidad
(Maven)
May 13, 2022
Joomla! Object Injection Vulnerability
Critical
CVE-2019-7743
was published
for
joomla/joomla-cms
(Composer)
May 13, 2022
Pippo RCE Vulnerability
Critical
CVE-2018-18240
was published
for
ro.pippo:pippo-core
(Maven)
May 13, 2022
Deserialization of Untrusted Data in Apache Batik
Critical
CVE-2018-8013
was published
for
org.apache.xmlgraphics:batik
(Maven)
May 13, 2022
Apache Flex BlazeDS unsafe deserialization
Critical
CVE-2017-5641
was published
for
org.apache.flex.blazeds:flex-messaging-core
(Maven)
May 13, 2022
Deserialization of Untrusted Data in Jenkins
Critical
CVE-2017-1000353
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Deserialization of Untrusted Data in Jenkins
Critical
CVE-2018-1000861
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Deserialization of Untrusted Data in topthink/framework
Critical
CVE-2021-23592
was published
for
topthink/framework
(Composer)
May 7, 2022
Deserialization of Untrusted Data in com.bstek.ureport:ureport2-console
Critical
CVE-2022-25767
was published
for
com.bstek.ureport:ureport2-console
(Maven)
May 3, 2022
Remote Code Execution in Laravel
Critical
CVE-2021-43503
was published
for
laravel/laravel
(Composer)
Apr 9, 2022
•
withdrawn
Deserialization of Untrusted Data in Apache Dubbo
Critical
CVE-2021-30179
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
Deserializer tampering in Apache Dubbo
Critical
CVE-2021-25641
was published
for
com.alibaba:dubbo
(Maven)
Mar 18, 2022
Deserialization of Untrusted Data in SinGooCMS.Utility
Critical
CVE-2022-0749
was published
for
SinGooCMS.Utility
(NuGet)
Mar 18, 2022
Deserialization of Untrusted Data in Jodd
Critical
CVE-2018-21234
was published
for
org.jodd:jodd-json
(Maven)
Feb 10, 2022
Deserialization of Untrusted Data in Apache Dubbo
Critical
CVE-2020-1948
was published
for
org.apache.dubbo:dubbo
(Maven)
Feb 10, 2022
Serialization vulnerability in Apache Tapestry
Critical
CVE-2020-17531
was published
for
org.apache.tapestry:tapestry-project
(Maven)
Feb 9, 2022
Remote code execution in DolphinScheduler
Critical
CVE-2020-11974
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Feb 9, 2022
Deserialization exploitation in Apache Dubbo
Critical
CVE-2020-11995
was published
for
org.apache.dubbo:dubbo-parent
(Maven)
Feb 9, 2022
Security Advisory for "Log4Shell"
Critical
GHSA-v57x-gxfj-484q
was published
for
com.hazelcast.jet:hazelcast-jet
(Maven)
Jan 21, 2022
Deserialization of Untrusted Data in Apache Log4j
Critical
CVE-2022-23307
was published
for
log4j:log4j
(Maven)
Jan 19, 2022
Deserialization of Untrusted Data in Dubbo
Critical
CVE-2021-43297
was published
for
org.apache.dubbo:dubbo
(Maven)
Jan 12, 2022
Deserialization of Untrusted Data in rust-cpuid
Critical
CVE-2021-45687
was published
for
raw-cpuid
(Rust)
Jan 6, 2022
ProTip!
Advisories are also available from the
GraphQL API