GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,386
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,480
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,012 advisories
Filter by severity
Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection....
Critical
Unreviewed
CVE-2025-26900
was published
Feb 25, 2025
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This...
High
Unreviewed
CVE-2025-27300
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager...
High
Unreviewed
CVE-2025-27301
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider...
Critical
Unreviewed
CVE-2025-26763
was published
Feb 22, 2025
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
High
Unreviewed
CVE-2024-13899
was published
Feb 22, 2025
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Critical
Unreviewed
CVE-2024-13789
was published
Feb 20, 2025
The application deserializes untrusted data without sufficiently verifying that the resulting...
Critical
Unreviewed
CVE-2024-37361
was published
Feb 20, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an...
High
Unreviewed
CVE-2024-45084
was published
Feb 19, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2024-28777
was published
Feb 19, 2025
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
High
Unreviewed
CVE-2024-13636
was published
Feb 18, 2025
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress...
High
Unreviewed
CVE-2024-13556
was published
Feb 18, 2025
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
Critical
Unreviewed
CVE-2024-12562
was published
Feb 15, 2025
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is...
High
Unreviewed
CVE-2024-13770
was published
Feb 13, 2025
A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-1186
was published
Feb 12, 2025
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-1177
was published
Feb 11, 2025
Utilization of a module presented a security risk by allowing the deserialization of untrusted...
Moderate
Unreviewed
CVE-2021-27017
was published
Feb 7, 2025
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2024-9664
was published
Feb 7, 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to...
High
Unreviewed
CVE-2025-0994
was published
Feb 6, 2025
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute...
Critical
Unreviewed
CVE-2025-20124
was published
Feb 5, 2025
Deserialization of Untrusted Data vulnerability in MagePeople Team Taxi Booking Manager for...
Critical
Unreviewed
CVE-2025-24661
was published
Feb 3, 2025
The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object...
Critical
Unreviewed
CVE-2024-13742
was published
Jan 30, 2025
NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a...
Moderate
Unreviewed
CVE-2024-0140
was published
Jan 28, 2025
Deserialization of Untrusted Data vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows...
Critical
Unreviewed
CVE-2025-24671
was published
Jan 27, 2025
Deserialization of Untrusted Data vulnerability in ThimPress FundPress allows Object Injection....
Critical
Unreviewed
CVE-2025-24601
was published
Jan 27, 2025
The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2024-12600
was published
Jan 25, 2025
ProTip!
Advisories are also available from the
GraphQL API