GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,076
Erlang
29
GitHub Actions
19
Go
1,895
Maven
5,000+
npm
3,630
NuGet
638
pip
3,244
Pub
10
RubyGems
862
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
242 advisories
Filter by severity
RCE vulnerability in Jenkins OpenShift Pipeline Plugin
High
CVE-2020-2167
was published
for
com.openshift.jenkins:openshift-pipeline
(Maven)
May 24, 2022
Remote Code Execution vulnerability in Jenkins Literate Plugin
High
CVE-2020-2158
was published
for
org.jenkins-ci.plugins:literate
(Maven)
May 24, 2022
RCE vulnerability in Google Kubernetes Engine Plugin
High
CVE-2020-2121
was published
for
org.jenkins-ci.plugins:google-kubernetes-engine
(Maven)
May 24, 2022
RCE vulnerability in RadarGun Plugin
High
CVE-2020-2123
was published
for
org.jenkins-ci.plugins:radargun
(Maven)
May 24, 2022
TYPO3 Insecure Deserialization in Query Generator & Query View
High
CVE-2019-19849
was published
for
typo3/cms
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8141
was published
for
magento/community-edition
(Composer)
May 24, 2022
Pimcore RCE via PHAR upload
High
CVE-2019-16317
was published
for
pimcore/pimcore
(Composer)
May 24, 2022
Shopware Insecure Deserialization Vulnerability
High
CVE-2019-12799
was published
for
shopware/shopware
(Composer)
May 24, 2022
Deserialization of Untrusted Data in Hazelcast
High
CVE-2016-10750
was published
for
com.hazelcast:hazelcast
(Maven)
May 24, 2022
gopkg.in/yaml.v3 Denial of Service
High
CVE-2022-28948
was published
for
gopkg.in/yaml.v3
(Go)
May 20, 2022
Deserialization of Untrusted Data in Apache Tomcat
High
CVE-2013-2185
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Restlet Arbitrary Java Code Execution via a serialized object
High
CVE-2013-4271
was published
for
org.restlet.jse:org.restlet
(Maven)
May 17, 2022
Deserialization of Untrusted Data in Apache Brooklyn
High
CVE-2016-8744
was published
for
org.apache.brooklyn:brooklyn
(Maven)
May 17, 2022
Apache James Privilege Escalation
High
CVE-2017-12628
was published
for
org.apache.james:james-project
(Maven)
May 17, 2022
Arbitrary code execution due to incomplete sandbox protection in Pipeline: Supporting APIs Plugin
High
CVE-2018-1000058
was published
for
org.jenkins-ci.plugins.workflow:workflow-support
(Maven)
May 14, 2022
Apache Geode unsafe deserialization of application objects
High
CVE-2017-15693
was published
for
org.apache.geode:geode-core
(Maven)
May 14, 2022
Deserialization of Untrusted Data in Apache OpenJPA
High
CVE-2013-1768
was published
for
org.apache.openjpa:openjpa
(Maven)
May 14, 2022
OISF suricata-update unsafely deserializes YAML data
High
CVE-2018-1000167
was published
for
suricata-update
(pip)
May 14, 2022
Apache NiFi JMS Deserialization issue
High
CVE-2018-1310
was published
for
org.apache.nifi:nifi
(Maven)
May 14, 2022
mPDF Unsafe Deserialization
High
CVE-2019-1000005
was published
for
mpdf/mpdf
(Composer)
May 14, 2022
RubyGems Deserialization of Untrusted Data vulnerability
High
CVE-2018-1000074
was published
for
org.jruby:jruby-stdlib
(RubyGems)
May 14, 2022
Deserialization of Untrusted Data in Infinispan
High
CVE-2017-15089
was published
for
org.infinispan:infinispan-core
(Maven)
May 14, 2022
Laravel Framework RCE Vulnerability
High
CVE-2018-15133
was published
for
laravel/framework
(Composer)
May 14, 2022
phpBB Remote Code Execution
High
CVE-2018-19274
was published
for
phpbb/phpbb
(Composer)
May 13, 2022
Deserialization of Untrusted Data in Jenkins
High
CVE-2017-2608
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API