GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,067
Erlang
29
GitHub Actions
19
Go
1,891
Maven
5,000+
npm
3,624
NuGet
638
pip
3,235
Pub
10
RubyGems
857
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
205 advisories
Filter by severity
Deserialization of Untrusted Data in jackson-databind
Critical
CVE-2020-8840
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Mar 4, 2020
Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
Critical
CVE-2018-19360
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jan 4, 2019
XML External Entity Reference (XXE) in jackson-databind
Critical
CVE-2018-14720
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jan 4, 2019
Deserialization of Untrusted Data in rust-cpuid
Critical
CVE-2021-45687
was published
for
raw-cpuid
(Rust)
Jan 6, 2022
Apache SOAP contains unauthenticated RPCRouterServlet
Critical
CVE-2022-45378
was published
for
soap:soap
(Maven)
Nov 14, 2022
JFinal Java Deserialization Vulnerability
Critical
CVE-2021-31649
was published
for
com.jfinal:jfinal
(Maven)
May 24, 2022
Spoon Library as used in Fork CMS allows PHP object injection
Critical
CVE-2019-15521
was published
for
spoon/library
(Composer)
May 24, 2022
QuantConnect Lean vulnerable to insecure deserialization
Critical
CVE-2020-20136
was published
for
QuantConnect.Common
(NuGet)
May 24, 2022
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Critical
CVE-2022-42468
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Oct 26, 2022
ipycache is vulnerable to Code Injection
Critical
CVE-2019-7539
was published
for
ipycache
(pip)
Mar 25, 2019
ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Critical
CVE-2020-8165
was published
for
activesupport
(RubyGems)
May 26, 2020
Unsafe deserialization in Apache MINA SSHD
Critical
CVE-2022-45047
was published
for
org.apache.sshd:sshd-common
(Maven)
Nov 16, 2022
Deserialization of Untrusted Data in superset
Critical
CVE-2018-8021
was published
for
superset
(pip)
Nov 9, 2018
Arbitrary code execution due to YAML deserialization
Critical
CVE-2021-37678
was published
for
tensorflow
(pip)
Aug 25, 2021
redis-store deserializes untrusted data
Critical
CVE-2017-1000248
was published
for
redis-store
(RubyGems)
Dec 6, 2017
Slanger Arbitrary command execution
Critical
CVE-2019-1010306
was published
for
slanger
(RubyGems)
Jul 16, 2019
NVFLARE unsafe deserialization due to Pickle
Critical
CVE-2022-34668
was published
for
nvflare
(pip)
Aug 31, 2022
Unsafe yaml deserialization in NVFlare
Critical
CVE-2022-31605
was published
for
nvflare
(pip)
Jun 22, 2022
Unsafe pyyaml load usage in PyAnyAPI
Critical
CVE-2017-16616
was published
for
pyanyapi
(pip)
May 13, 2022
Unsafe deserialisation in the PKI implementation scheme of NVFlare
Critical
CVE-2022-31604
was published
for
nvflare
(pip)
Jun 22, 2022
PyYAML insecurely deserializes YAML strings leading to arbitrary code execution
Critical
CVE-2017-18342
was published
for
pyyaml
(pip)
Jan 4, 2019
Unsafe deserialization in owlmixin
Critical
CVE-2017-16618
was published
for
owlmixin
(pip)
Jul 13, 2018
Uncontrolled deserialization of a pickled object in rediswrapper allows attackers to execute arbitrary scripts
Critical
CVE-2019-17206
was published
for
rediswrapper
(pip)
Nov 20, 2019
Remote Code Execution in scratch-vm
Critical
CVE-2020-14000
was published
for
scratch-vm
(npm)
Jul 27, 2020
Polymorphic Typing issue in FasterXML jackson-databind
Critical
CVE-2019-16335
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 23, 2019
ProTip!
Advisories are also available from the
GraphQL API