GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,564 advisories
Filter by severity
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for...
High
Unreviewed
CVE-2024-13906
was published
Mar 7, 2025
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting...
Critical
Unreviewed
CVE-2025-27816
was published
Mar 7, 2025
A deserialization of untrusted data vulnerability exists in NI G Web Development Software that...
High
Unreviewed
CVE-2024-12742
was published
Mar 6, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13777
was published
Mar 5, 2025
The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection...
Critical
Unreviewed
CVE-2024-13787
was published
Mar 5, 2025
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions...
Critical
Unreviewed
CVE-2025-0912
was published
Mar 4, 2025
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection...
High
Unreviewed
CVE-2025-26999
was published
Mar 3, 2025
Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection....
High
Unreviewed
CVE-2025-26885
was published
Mar 3, 2025
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory...
High
Unreviewed
CVE-2025-26967
was published
Mar 3, 2025
Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk...
High
Unreviewed
CVE-2024-47092
was published
Mar 3, 2025
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection...
High
Unreviewed
CVE-2024-13833
was published
Mar 1, 2025
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable....
Moderate
Unreviewed
CVE-2025-0769
was published
Feb 28, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all...
High
Unreviewed
CVE-2024-13831
was published
Feb 28, 2025
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an...
Moderate
Unreviewed
CVE-2025-0767
was published
Feb 27, 2025
Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection....
Critical
Unreviewed
CVE-2025-26900
was published
Feb 25, 2025
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This...
High
Unreviewed
CVE-2025-27300
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager...
High
Unreviewed
CVE-2025-27301
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider...
Critical
Unreviewed
CVE-2025-26763
was published
Feb 22, 2025
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
High
Unreviewed
CVE-2024-13899
was published
Feb 22, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Critical
Unreviewed
CVE-2024-13789
was published
Feb 20, 2025
The application deserializes untrusted data without sufficiently verifying that the resulting...
Critical
Unreviewed
CVE-2024-37361
was published
Feb 20, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an...
High
Unreviewed
CVE-2024-45084
was published
Feb 19, 2025
ProTip!
Advisories are also available from the
GraphQL API