GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,972
Erlang
29
GitHub Actions
16
Go
1,762
Maven
4,983
npm
3,518
NuGet
609
pip
3,094
Pub
10
RubyGems
833
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
73 advisories
Filter by severity
Object injection in PHPMailer/PHPMailer
Critical
CVE-2020-36326
was published
for
phpmailer/phpmailer
(Composer)
May 4, 2021
Directory Traversal in typo3/phar-stream-wrapper
Critical
CVE-2019-11831
was published
for
drupal/core
(Composer)
Sep 30, 2021
Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data
High
CVE-2019-6338
was published
for
drupal/drupal
(Composer)
Dec 2, 2019
PharStreamWrapper for Typo3 unsafe deserialization vulnerability
Critical
CVE-2019-11830
was published
for
typo3/phar-stream-wrapper
(Composer)
May 24, 2022
Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS
High
CVE-2020-15098
was published
for
typo3/cms
(Composer)
Jul 29, 2020
Insecure Deserialization in Backend User Settings in TYPO3 CMS
High
CVE-2020-11067
was published
for
typo3/cms
(Composer)
May 13, 2020
Deserialization of untrusted data in Symfony
High
CVE-2019-10912
was published
for
symfony/cache
(Composer)
Feb 12, 2020
TCPDF vulnerable to attackers triggering deserialization of arbitrary data
Critical
CVE-2018-17057
was published
for
fooman/tcpdf
(Composer)
Oct 6, 2022
Potential Remote Code Execution in TYPO3 with mediace extension
Critical
CVE-2020-15086
was published
for
friendsoftypo3/mediace
(Composer)
Jul 29, 2020
Deserialization of Untrusted Data in codeception/codeception
Critical
CVE-2021-23420
was published
for
codeception/codeception
(Composer)
Sep 1, 2021
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8141
was published
for
magento/community-edition
(Composer)
May 24, 2022
Phar object injection in PHPMailer
High
CVE-2018-19296
was published
for
phpmailer/phpmailer
(Composer)
Mar 5, 2020
Deserialization of Untrusted Data in Codeigniter4
High
CVE-2022-21647
was published
for
codeigniter4/framework
(Composer)
Jan 6, 2022
Unsafe deserialization in SmtpTransport in CakePHP
High
CVE-2019-11458
was published
for
cakephp/cakephp
(Composer)
Dec 2, 2019
Silverstripe CMS Arbitrary Code Execution
Moderate
CVE-2011-4962
was published
for
silverstripe/cms
(Composer)
May 17, 2022
PHPEMS Deserialization of Untrusted Data vulnerability
Moderate
CVE-2023-6654
was published
for
phpems/phpems
(Composer)
Dec 10, 2023
Magento deserialization vulnerability
Critical
CVE-2020-3716
was published
for
magento/community-edition
(Composer)
May 24, 2022
yiisoft/yii deserializing untrusted user input can lead to remote code execution
High
CVE-2023-47130
was published
for
yiisoft/yii
(Composer)
Nov 14, 2023
Orchid Deserialization of Untrusted Data vulnerability leads to Remote Code Execution
Critical
CVE-2023-36825
was published
for
orchid/platform
(Composer)
Jul 11, 2023
Snappy PHAR deserialization vulnerability
Critical
CVE-2023-41330
was published
for
knplabs/knp-snappy
(Composer)
Sep 8, 2023
mPDF Unsafe Deserialization
High
CVE-2019-1000005
was published
for
mpdf/mpdf
(Composer)
May 14, 2022
Laravel Framework Deserialization Vulnerability
Critical
CVE-2019-9081
was published
for
laravel/framework
(Composer)
May 14, 2022
Joomla! Object Injection Vulnerability
Critical
CVE-2019-7743
was published
for
joomla/joomla-cms
(Composer)
May 13, 2022
Deserialization of Untrusted Data in topthink/framework
Critical
CVE-2021-36564
was published
for
topthink/framework
(Composer)
Dec 10, 2021
Deserialization of Untrusted Data in librenms/librenms
High
CVE-2022-3525
was published
for
librenms/librenms
(Composer)
Nov 20, 2022
ProTip!
Advisories are also available from the
GraphQL API