GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,830 advisories
Filter by severity
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer...
High
Unreviewed
CVE-2026-68772
was published
Aug 7, 2026
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache...
Critical
Unreviewed
CVE-2026-71560
was published
Aug 7, 2026
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an...
High
Unreviewed
CVE-2026-71559
was published
Aug 7, 2026
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache...
Critical
Unreviewed
CVE-2026-71558
was published
Aug 7, 2026
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of...
Critical
Unreviewed
CVE-2026-16258
was published
Aug 7, 2026
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute...
Critical
Unreviewed
CVE-2026-50515
was published
Aug 7, 2026
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
High
Unreviewed
CVE-2026-65549
was published
Aug 6, 2026
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Critical
Unreviewed
CVE-2026-65552
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Critical
Unreviewed
CVE-2026-65556
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Critical
Unreviewed
CVE-2026-65575
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Critical
Unreviewed
CVE-2026-65571
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Critical
Unreviewed
CVE-2026-65572
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Critical
Unreviewed
CVE-2026-65573
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Critical
Unreviewed
CVE-2026-65581
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Critical
Unreviewed
CVE-2026-65574
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Critical
Unreviewed
CVE-2026-65577
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Critical
Unreviewed
CVE-2026-65576
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Critical
Unreviewed
CVE-2026-65579
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Critical
Unreviewed
CVE-2026-65578
was published
Aug 6, 2026
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Critical
Unreviewed
CVE-2026-28139
was published
Aug 6, 2026
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native...
Critical
Unreviewed
CVE-2026-66909
was published
Aug 6, 2026
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2...
Critical
Unreviewed
CVE-2026-70426
was published
Aug 5, 2026
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes...
High
Unreviewed
CVE-2026-71294
was published
Aug 5, 2026
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
High
Unreviewed
CVE-2026-71281
was published
Aug 5, 2026
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
...
Critical
Unreviewed
CVE-2026-61484
was published
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API