GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,513
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,862 advisories
Filter by severity
The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority -...
Critical
Unreviewed
CVE-2025-7639
was published
Aug 14, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of...
Moderate
Unreviewed
CVE-2026-10571
was published
Aug 13, 2026
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig...
High
Unreviewed
CVE-2026-66256
was published
Aug 13, 2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
High
Unreviewed
CVE-2026-28176
was published
Aug 13, 2026
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Critical
Unreviewed
CVE-2026-28149
was published
Aug 13, 2026
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
High
Unreviewed
CVE-2026-27380
was published
Aug 13, 2026
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability...
High
Unreviewed
CVE-2026-73325
was published
Aug 12, 2026
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a...
Moderate
Unreviewed
CVE-2026-59242
was published
Aug 12, 2026
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input`...
High
Unreviewed
CVE-2026-67260
was published
Aug 12, 2026
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its...
High
Unreviewed
CVE-2026-67587
was published
Aug 12, 2026
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()`...
High
Unreviewed
CVE-2026-58076
was published
Aug 12, 2026
A party with write access to stored session data may affect JFrog Artifactory under specific...
Moderate
Unreviewed
CVE-2026-68756
was published
Aug 12, 2026
An insecure handling of serialized objects vulnerability was found in the one of the service of...
High
Unreviewed
CVE-2026-18634
was published
Aug 11, 2026
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could...
High
Unreviewed
CVE-2026-48397
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-70321
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-66808
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-66805
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized...
High
Unreviewed
CVE-2026-65815
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-65665
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-65658
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-65663
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-64901
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-63516
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2026-63514
was published
Aug 11, 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-62912
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API