GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,681
Maven
5,000+
npm
4,310
NuGet
760
pip
4,083
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
239 advisories
Filter by severity
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Nov 25, 2025
The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Moderate
Unreviewed
CVE-2025-9191
was published
Nov 26, 2025
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows...
Moderate
Unreviewed
CVE-2025-66073
was published
Nov 21, 2025
Drupal core allows Object Injection
Moderate
CVE-2025-13081
was published
for
drupal/core
(Composer)
Nov 18, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object...
Moderate
Unreviewed
CVE-2025-60216
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object...
Moderate
Unreviewed
CVE-2025-60215
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to...
Moderate
Unreviewed
CVE-2025-60224
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync...
Moderate
Unreviewed
CVE-2025-60221
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder...
Moderate
Unreviewed
CVE-2025-49380
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing...
Moderate
Unreviewed
CVE-2025-60210
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object...
Moderate
Unreviewed
CVE-2025-31634
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object...
Moderate
Unreviewed
CVE-2025-32283
was published
Oct 22, 2025
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is...
Moderate
Unreviewed
CVE-2025-63617
was published
Nov 10, 2025
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5680
was published
Jun 5, 2025
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5679
was published
Jun 5, 2025
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-12305
was published
Oct 27, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all...
Moderate
Unreviewed
CVE-2025-8871
was published
Nov 5, 2025
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2025-30761
was published
Jul 15, 2025
cryptidy allows code execution via untrusted data due to pickle.loads
Moderate
CVE-2025-63675
was published
for
cryptidy
(pip)
Oct 31, 2025
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Moderate
CVE-2025-12058
was published
for
keras
(pip)
Oct 29, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-11938
was published
Oct 19, 2025
Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle Deserialization
Moderate
GHSA-cq46-m9x9-j8w2
was published
for
scapy
(pip)
Oct 22, 2025
ProTip!
Advisories are also available from the
GraphQL API