GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,552 advisories
Filter by severity
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable....
Moderate
Unreviewed
CVE-2025-0769
was published
Feb 28, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all...
High
Unreviewed
CVE-2024-13831
was published
Feb 28, 2025
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an...
Moderate
Unreviewed
CVE-2025-0767
was published
Feb 27, 2025
Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection....
Critical
Unreviewed
CVE-2025-26900
was published
Feb 25, 2025
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This...
High
Unreviewed
CVE-2025-27300
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager...
High
Unreviewed
CVE-2025-27301
was published
Feb 24, 2025
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider...
Critical
Unreviewed
CVE-2025-26763
was published
Feb 22, 2025
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
High
Unreviewed
CVE-2024-13899
was published
Feb 22, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Critical
Unreviewed
CVE-2024-13789
was published
Feb 20, 2025
The application deserializes untrusted data without sufficiently verifying that the resulting...
Critical
Unreviewed
CVE-2024-37361
was published
Feb 20, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2024-28777
was published
Feb 19, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an...
High
Unreviewed
CVE-2024-45084
was published
Feb 19, 2025
The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
High
Unreviewed
CVE-2024-13636
was published
Feb 18, 2025
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress...
High
Unreviewed
CVE-2024-13556
was published
Feb 18, 2025
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
Critical
Unreviewed
CVE-2024-12562
was published
Feb 15, 2025
Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
Critical
CVE-2024-56180
was published
for
org.apache.eventmesh:eventmesh-meta-raft
(Maven)
Feb 14, 2025
Apache Ignite: Possible RCE when deserializing incoming messages by the server node
Critical
CVE-2024-52577
was published
for
org.apache.ignite:ignite-core
(Maven)
Feb 14, 2025
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is...
High
Unreviewed
CVE-2024-13770
was published
Feb 13, 2025
A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-1186
was published
Feb 12, 2025
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-1177
was published
Feb 11, 2025
Utilization of a module presented a security risk by allowing the deserialization of untrusted...
Moderate
Unreviewed
CVE-2021-27017
was published
Feb 7, 2025
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2024-9664
was published
Feb 7, 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to...
High
Unreviewed
CVE-2025-0994
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API