GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,368
Maven
5,000+
npm
3,988
NuGet
720
pip
3,779
Pub
12
RubyGems
926
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
341 advisories
Filter by severity
Apache InLong vulnerable to Deserialization of Untrusted Data
High
CVE-2022-40955
was published
for
org.apache.inlong:inlong-common
(Maven)
Sep 21, 2022
Apache Geode vulnerable to Deserialization of Untrusted Data
Critical
CVE-2022-37021
was published
for
org.apache.geode:geode-core
(Maven)
Sep 1, 2022
Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11
High
CVE-2022-37022
was published
for
org.apache.geode:geode-core
(Maven)
Sep 1, 2022
Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data
Moderate
CVE-2022-37023
was published
for
org.apache.geode:geode-core
(Maven)
Sep 1, 2022
Deserialization of Untrusted Data in Apache Hadoop YARN
High
CVE-2021-25642
was published
for
org.apache.hadoop:hadoop-yarn-server
(Maven)
Aug 26, 2022
jackson-databind vulnerable to unsafe deserialization
High
CVE-2020-10650
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 15, 2022
fabric8 kubernetes-client vulnerable
Moderate
CVE-2021-4178
was published
for
io.fabric8:kubernetes-client
(Maven)
Jul 15, 2022
User account escalation in Apache Hadoop
High
CVE-2021-33036
was published
for
org.apache.hadoop:hadoop-yarn-server-common
(Maven)
Jun 16, 2022
Unsafe deserialization in com.alibaba:fastjson
High
CVE-2022-25845
was published
for
com.alibaba:fastjson
(Maven)
Jun 11, 2022
Deserialization of Untrusted Data in Apache Tapestry
Critical
CVE-2019-0195
was published
for
org.apache.tapestry:tapestry-core
(Maven)
May 24, 2022
Deserialization of Untrusted Data in Spring AMQP
Moderate
CVE-2021-22097
was published
for
org.springframework.amqp:spring-amqp
(Maven)
May 24, 2022
RCE vulnerability in Jenkins Code Coverage API Plugin
High
CVE-2021-21677
was published
for
io.jenkins.plugins:code-coverage-api
(Maven)
May 24, 2022
JFinal Java Deserialization Vulnerability
Critical
CVE-2021-31649
was published
for
com.jfinal:jfinal
(Maven)
May 24, 2022
Improper handling of REST API XML deserialization errors in Jenkins
High
CVE-2021-21604
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution
High
CVE-2020-10721
was published
for
io.fabric8:fabric8-maven-plugin
(Maven)
May 24, 2022
Maven Extension plugin for Gradle Enterprise vulnerable to Deserialization of Untrusted Data
High
CVE-2020-15777
was published
for
com.gradle:gradle-enterprise-maven-extension
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability
High
CVE-2020-15842
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
High
CVE-2020-2211
was published
for
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
(Maven)
May 24, 2022
Wildfly Unsafe Deserialization Vulnerability
High
CVE-2020-10740
was published
for
org.wildfly:wildfly-parent
(Maven)
May 24, 2022
Deserialization of Untrusted Data in Spring Batch
High
CVE-2020-5411
was published
for
org.springframework.batch:spring-batch-core
(Maven)
May 24, 2022
OpenNMS Horizon RCE via Unsafe Deserialization
High
CVE-2020-12760
was published
for
org.opennms.core:org.opennms.core.daemon
(Maven)
May 24, 2022
RCE vulnerability in SCM Filter Jervis Plugin
High
CVE-2020-2189
was published
for
io.jenkins.plugins:scm-filter-jervis
(Maven)
May 24, 2022
RCE vulnerability in Jenkins AWS SAM Plugin
High
CVE-2020-2180
was published
for
io.jenkins.plugins:aws-sam
(Maven)
May 24, 2022
RCE vulnerability in Jenkins Yaml Axis Plugin
High
CVE-2020-2179
was published
for
org.jenkins-ci.plugins:yaml-axis
(Maven)
May 24, 2022
Deserialization of Untrusted Data in Apache Dubbo
Moderate
CVE-2019-17564
was published
for
org.apache.dubbo:dubbo-rpc-http-invoker
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API