GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,947 advisories
Filter by severity
Keras framework vulnerable to deserialization of untrusted data
Critical
CVE-2025-49655
was published
for
keras
(pip)
Oct 17, 2025
pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
Critical
CVE-2025-62515
was published
for
pyquokka
(pip)
Oct 17, 2025
Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-54539
was published
for
Apache.NMS.AMQP
(NuGet)
Oct 16, 2025
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-59285
was published
Oct 14, 2025
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized...
Critical
Unreviewed
CVE-2025-59287
was published
Oct 14, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-59237
was published
Oct 14, 2025
Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to...
High
Unreviewed
CVE-2025-11622
was published
Oct 13, 2025
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The...
Moderate
Unreviewed
CVE-2025-61505
was published
Oct 10, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the...
Moderate
Unreviewed
CVE-2025-60830
was published
Oct 8, 2025
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-60834
was published
Oct 8, 2025
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the ...
Moderate
Unreviewed
CVE-2025-60828
was published
Oct 8, 2025
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
Moderate
CVE-2025-61765
was published
for
python-socketio
(pip)
Oct 7, 2025
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-11345
was published
Oct 6, 2025
Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on...
Critical
Unreviewed
CVE-2025-10363
was published
Oct 6, 2025
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-49886
was published
Oct 6, 2025
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code...
Critical
Unreviewed
CVE-2025-58384
was published
Sep 26, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy...
Critical
Unreviewed
CVE-2025-26399
was published
Sep 23, 2025
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object...
High
Unreviewed
CVE-2025-58662
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for...
High
Unreviewed
CVE-2025-57919
was published
Sep 22, 2025
Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector allows Object...
High
Unreviewed
CVE-2025-53465
was published
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API