GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,782 advisories
Filter by severity
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input...
High
Unreviewed
CVE-2026-12583
was published
Jul 14, 2026
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to...
High
Unreviewed
CVE-2026-58233
was published
Jul 14, 2026
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass
Critical
CVE-2026-47065
was published
for
org.apache.mina:mina-core
(Maven)
Jun 3, 2026
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object...
Critical
Unreviewed
CVE-2026-59518
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial...
High
Unreviewed
CVE-2026-59521
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18...
Critical
Unreviewed
CVE-2026-57744
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography...
Critical
Unreviewed
CVE-2026-57770
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection...
Critical
Unreviewed
CVE-2026-57724
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object...
Critical
Unreviewed
CVE-2026-57738
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events...
High
Unreviewed
CVE-2026-57713
was published
Jul 13, 2026
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object...
High
Unreviewed
CVE-2026-57371
was published
Jul 13, 2026
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized...
High
Unreviewed
CVE-2026-58281
was published
Jul 11, 2026
Jaspersoft Reports: Java Deserialization Vulnerability Lleads to Remote Code Execution (RCE)
High
CVE-2026-6009
was published
for
net.sf.jasperreports:jasperreports
(Maven)
May 19, 2026
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
High
CVE-2026-54071
was published
for
BabelDOC
(pip)
Jul 10, 2026
Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
High
CVE-2026-45162
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of...
High
Unreviewed
CVE-2026-54469
was published
Jul 10, 2026
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
High
CVE-2016-0750
was published
for
org.infinispan:infinispan-core
(Maven)
May 13, 2022
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which...
Critical
Unreviewed
CVE-2026-50633
was published
Jun 12, 2026
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can...
Critical
Unreviewed
CVE-2026-50632
was published
Jun 12, 2026
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
High
GHSA-rpj2-4hq8-938g
was published
for
vcrpy
(pip)
Jun 19, 2026
Apache Airflow has a Deserialization of Untrusted Data vulnerability
High
CVE-2026-42359
was published
for
apache-airflow
(pip)
Jun 1, 2026
YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize
Critical
CVE-2026-52777
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Apache Airflow Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-45360
was published
for
apache-airflow
(pip)
Jun 1, 2026
A Remote Code Execution vulnerability exists in PcVue from version 8.10 onward, due to the unsafe...
Critical
Unreviewed
CVE-2020-26867
was published
May 24, 2022
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
Critical
CVE-2022-32511
was published
for
jmespath
(RubyGems)
Jun 7, 2022
ProTip!
Advisories are also available from the
GraphQL API