GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
435 advisories
Filter by severity
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM possibly allows bypass of IP Filters
High
CVE-2025-52487
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DotVVM allows path traversal when deployed in Debug mode
High
GHSA-6q65-j4jw-9cg8
was published
for
DotVVM
(NuGet)
Jun 19, 2025
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
High
CVE-2025-30399
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jun 11, 2025
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
High
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
High
GHSA-f87w-3j5w-v58p
was published
for
CefSharp.OffScreen
(NuGet)
Apr 12, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
High
CVE-2025-24043
was published
for
dotnet-debugger-extensions
(NuGet)
Mar 7, 2025
DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.Api
High
GHSA-vc29-vg52-6643
was published
for
OpenTelemetry.AutoInstrumentation
(NuGet)
Mar 6, 2025
Out-of-bounds Write in SixLabors ImageSharp
High
CVE-2025-27598
was published
for
SixLabors.ImageSharp
(NuGet)
Mar 6, 2025
Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard Stack
High
GHSA-qv5f-57gw-vx3h
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Feb 10, 2025
•
withdrawn
Property reflection in System.Linq.Dynamic.Core
High
CVE-2024-51417
was published
for
System.Linq.Dynamic.Core
(NuGet)
Jan 21, 2025
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21176
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21172
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
High
CVE-2025-21171
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Git Credential Manager carriage-return character in remote URL allows malicious repository to leak credentials
High
CVE-2024-50338
was published
for
git-credential-manager
(NuGet)
Jan 14, 2025
Oqtane Framework Incorrect Access Control vulnerability
High
CVE-2024-55470
was published
for
Oqtane.Framework
(NuGet)
Dec 20, 2024
TShock Security Escalation Exploit
High
GHSA-hvm9-wc8j-mgrc
was published
for
TShock
(NuGet)
Dec 18, 2024
DotNetZip Directory Traversal vulnerability
High
CVE-2024-48510
was published
for
DotNetZip
(NuGet)
Nov 13, 2024
.NET Denial of Service Vulnerability
High
CVE-2024-43499
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
Duplicate Advisory: .NET and Visual Studio Denial of Service Vulnerability
High
GHSA-wmm6-pgp8-29hg
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
•
withdrawn
Apache Lucene.Net.Replicator Deserialization of Untrusted Data vulnerability
High
CVE-2024-43383
was published
for
Lucene.Net.Replicator
(NuGet)
Oct 31, 2024
Security Update for the OPC UA .NET Standard Stack
High
GHSA-qm9f-c3v9-wphv
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Oct 18, 2024
ProTip!
Advisories are also available from the
GraphQL API