Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,131 advisories

Loading
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers High
CVE-2026-100368 was published for AlastairLundy.CliInvoke.Specializations (NuGet) Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory High
CVE-2026-100369 was published for AlastairLundy.CliInvoke (NuGet) Sep 25, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
MPXJ: XXE Vulnerability in MerlinReader High
CVE-2026-61570 was published for MPXJ.Net (RubyGems) Sep 22, 2026
dyingman1 Credited to dyingman1
Steeltoe: Header-forwarded client cert lacks proof of private-key possession Moderate
CVE-2026-81868 was published for Steeltoe.Security.Authorization.Certificate (NuGet) Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) High
CVE-2026-81516 was published for Steeltoe.Discovery.Consul (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) High
CVE-2026-81515 was published for Steeltoe.Discovery.Eureka (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Moderate
CVE-2026-75523 was published for Steeltoe.Management.Endpoint (NuGet) Sep 17, 2026
manus-use Credited to manus-use
SSH.NET: ScpClient allows server-side RCE via default SCP path handling High
CVE-2026-85756 was published for SSH.NET (NuGet) Sep 17, 2026
Nadav0077 Credited to Nadav0077
suryadina Credited to suryadina
Marten's LINQ provider has SQL injection via unescaped string literals Critical
CVE-2026-75513 was published for Marten (NuGet) Sep 17, 2026
svenclaesson Credited to svenclaesson
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS High
CVE-2026-81192 was published for OpenTelemetry.Resources.Host (NuGet) Sep 16, 2026
martincostello Credited to martincostello and lachmatt lachmatt lachmatt
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability Moderate
CVE-2026-69304 was published for Microsoft.AspNetCore.Server.IISIntegration (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-69522 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
CVE-2026-69439 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-71328 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability High
CVE-2026-50646 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Sep 8, 2026
Microsoft QUIC: Remote Code Execution Vulnerability Critical
CVE-2026-62815 was published for Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet) Sep 8, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62900 was published for Microsoft.Build.Tasks.Git (NuGet) Sep 8, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
GHSA-4qhr-qf46-fcrx was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
GHSA-q72m-f2r4-w4cw was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
GHSA-mqvm-gmc4-6rv2 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability Moderate
GHSA-v3f6-m9j2-437p was published for Microsoft.AspNetCore.Server.IISIntegration (NuGet) Sep 8, 2026 • withdrawn
ImageMagick: Memory Leak when providing invalid options to the cli Low
GHSA-cvhv-g4rq-3hmw was published for Magick.NET-Q16-AnyCPU (NuGet) Sep 2, 2026
007bsd Credited to 007bsd and Junaid-PK Junaid-PK Junaid-PK
manus-use Credited to manus-use
ProTip! Advisories are also available from the GraphQL API