GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
711 advisories
Filter by severity
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Moderate
CVE-2025-48378
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Moderate
CVE-2025-48377
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
DNN site Import could use an external source with a crafted request
Low
CVE-2025-48376
was published
for
DotNetNuke.SiteExportImport
(NuGet)
May 23, 2025
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Low
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
CVE-2025-47280
was published
for
Umbraco.Forms
(NuGet)
May 13, 2025
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Moderate
CVE-2025-46736
was published
for
Umbraco.Cms
(NuGet)
May 6, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46326
was published
for
Snowflake.Data
(NuGet)
Apr 28, 2025
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-29953
was published
for
Apache.NMS.ActiveMQ
(NuGet)
Apr 18, 2025
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
High
GHSA-f87w-3j5w-v58p
was published
for
CefSharp.OffScreen
(NuGet)
Apr 12, 2025
Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs
Moderate
CVE-2025-32016
was published
for
Microsoft.Identity.Abstractions
(NuGet)
Apr 9, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-32372
was published
for
DotNetNuke.Core
(NuGet)
Apr 9, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Moderate
CVE-2025-27602
was published
for
Umbraco.Cms.Web.Backoffice
(NuGet)
Mar 11, 2025
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Moderate
CVE-2025-27601
was published
for
Umbraco.Cms.Api.Management
(NuGet)
Mar 11, 2025
Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability
High
CVE-2025-24043
was published
for
dotnet-debugger-extensions
(NuGet)
Mar 7, 2025
DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.Api
High
GHSA-vc29-vg52-6643
was published
for
OpenTelemetry.AutoInstrumentation
(NuGet)
Mar 6, 2025
Out-of-bounds Write in SixLabors ImageSharp
High
CVE-2025-27598
was published
for
SixLabors.ImageSharp
(NuGet)
Mar 6, 2025
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
Moderate
CVE-2025-27513
was published
for
OpenTelemetry.Api
(NuGet)
Mar 5, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42512
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
Mar 3, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua.Bindings.Https
(NuGet)
Mar 3, 2025
AutoQueryable leaks sensitive information
Moderate
CVE-2024-57716
was published
for
AutoQueryable
(NuGet)
Feb 20, 2025
Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credentials Access Tokens
Moderate
CVE-2025-26620
was published
for
Duende.AccessTokenManagement
(NuGet)
Feb 19, 2025
ProTip!
Advisories are also available from the
GraphQL API