GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,796
Maven
5,000+
npm
4,410
NuGet
772
pip
4,181
Pub
12
RubyGems
965
Rust
1,078
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,122 advisories
Filter by severity
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker...
Moderate
Unreviewed
CVE-2026-22187
was published
Jan 7, 2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows...
Critical
Unreviewed
CVE-2025-47552
was published
Jan 7, 2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows...
High
Unreviewed
CVE-2025-47553
was published
Jan 6, 2026
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection...
High
Unreviewed
CVE-2025-31047
was published
Jan 5, 2026
Feast vulnerable to Deserialization of Untrusted Data
High
CVE-2025-11157
was published
for
feast
(pip)
Jan 1, 2026
FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-15276
was published
Dec 31, 2025
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of...
Moderate
Unreviewed
CVE-2025-15375
was published
Dec 31, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-r8g5-cgf2-4m4m
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling pty.spawn
High
GHSA-vqmv-47xg-9wpr
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan vulnerable to Arbitrary File Writing
High
GHSA-m273-6v24-x4m4
was published
for
picklescan
(pip)
Dec 29, 2025
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
High
CVE-2025-67729
was published
for
lmdeploy
(pip)
Dec 26, 2025
Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers...
Critical
Unreviewed
CVE-2025-68038
was published
Dec 24, 2025
Tencent NeuralNLP-NeuralClassifier _load_checkpoint Deserialization of Untrusted Data Remote Code...
High
Unreviewed
CVE-2025-13708
was published
Dec 24, 2025
Tencent HunyuanDiT merge Deserialization of Untrusted Data Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-13712
was published
Dec 24, 2025
Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution...
High
Unreviewed
CVE-2025-13709
was published
Dec 24, 2025
Tencent MedicalNet generate_model Deserialization of Untrusted Data Remote Code Execution...
High
Unreviewed
CVE-2025-13714
was published
Dec 24, 2025
Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution...
High
Unreviewed
CVE-2025-13706
was published
Dec 24, 2025
Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-13711
was published
Dec 24, 2025
Tencent Hunyuan3D-1 load_pretrained Deserialization of Untrusted Data Remote Code Execution...
High
Unreviewed
CVE-2025-13713
was published
Dec 24, 2025
ProTip!
Advisories are also available from the
GraphQL API