GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
116 advisories
Filter by severity
TYPO3 CMS has Insecure Deserialization via Core API
Moderate
CVE-2026-49740
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
PHPSpreadsheet has a patch bypass for CVE-2026-34084
Critical
CVE-2026-45034
was published
for
phpoffice/phpspreadsheet
(Composer)
Jun 8, 2026
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
High
CVE-2026-45077
was published
for
symfony/monolog-bridge
(Composer)
May 27, 2026
Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
High
CVE-2026-45162
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
torrentpier has PHP Serialize Injections
Critical
GHSA-h29g-c9cx-c73q
was published
for
torrentpier/torrentpier
(Composer)
May 11, 2026
Grav has Insecure Deserialization in File Cache
Low
CVE-2026-7317
was published
for
getgrav/grav
(Composer)
May 5, 2026
Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass
Critical
GHSA-vj3m-2g9h-vm4p
was published
for
getgrav/grav
(Composer)
May 5, 2026
PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
Critical
CVE-2026-34084
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
High
CVE-2026-25524
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
Low
CVE-2026-35537
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
OpenSTAManager Affected by Remote Code Execution via Insecure Deserialization in OAuth2
High
CVE-2026-29782
was published
for
devcode-it/openstamanager
(Composer)
Apr 1, 2026
Saloon has insecure deserialization in AccessTokenAuthenticator
High
CVE-2026-33942
was published
for
saloonphp/saloon
(Composer)
Mar 27, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Concrete CMS vulnerable to Remote Code Execution by stored PHP object injection
High
CVE-2026-3452
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function
Low
CVE-2026-2898
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()
High
CVE-2026-27206
was published
for
zumba/json-serializer
(Composer)
Feb 19, 2026
MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution
High
GHSA-r33w-fg8j-9c94
was published
for
cesargb/laravel-magiclink
(Composer)
Feb 12, 2026
PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
High
CVE-2026-24765
was published
for
phpunit/phpunit
(Composer)
Jan 27, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Moderate
CVE-2026-0895
was published
for
cpsit/typo3-mailqueue
(Composer)
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
Critical
CVE-2026-23524
was published
for
laravel/reverb
(Composer)
Jan 21, 2026
TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool
Moderate
CVE-2026-0859
was published
for
typo3/cms-core
(Composer)
Jan 13, 2026
Drupal core allows Object Injection
Moderate
CVE-2025-13081
was published
for
drupal/core
(Composer)
Nov 18, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Adminer PHP Object Injection issue leads to Denial of Service
High
CVE-2025-43960
was published
for
vrana/adminer
(Composer)
Aug 25, 2025
laravel-auth0 SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-c42h-56wx-h85q
was published
for
auth0/login
(Composer)
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API