GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
43 advisories
Filter by severity
.NET Remote Code Execution Vulnerability
Critical
CVE-2024-43498
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
Critical
CVE-2024-35264
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 9, 2024
Duplicate Advisory: .NET and Visual Studio Remote Code Execution Vulnerability
Critical
GHSA-8rxm-6783-qh55
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
•
withdrawn
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
Critical
CVE-2024-51501
was published
for
Refit
(NuGet)
Nov 4, 2024
CLSA Directory Traversal vulnerability
Critical
CVE-2024-28698
was published
for
Csla
(NuGet)
Jul 22, 2024
Duplicate Advisory: NuGet Client Security Feature Bypass Vulnerability
Critical
GHSA-jw42-5m4v-9c8g
was published
for
NuGet.CommandLine
(NuGet)
Jan 9, 2024
•
withdrawn
NuGet Client Security Feature Bypass Vulnerability
Critical
CVE-2024-0057
was published
for
NuGet.CommandLine
(NuGet)
Feb 13, 2024
Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
Critical
CVE-2014-4172
was published
for
DotNetCasClient
(Composer)
May 17, 2022
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
Critical
CVE-2024-21386
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Feb 13, 2024
.NET Core Remote Code Execution Vulnerability
Critical
CVE-2021-26701
was published
for
System.Text.Encodings.Web
(NuGet)
Apr 21, 2021
Remote Code Execution in AjaxNetProfessional
Critical
CVE-2021-23758
was published
for
AjaxNetProfessional
(NuGet)
Dec 16, 2021
Dynamic Linq vulnerable to remote code execution
Critical
CVE-2023-32571
was published
for
System.Linq.Dynamic.Core
(NuGet)
Jun 22, 2023
ChakraCore RCE Vulnerability
Critical
CVE-2017-0252
was published
for
Microsoft.ChakraCore
(NuGet)
May 17, 2022
New Relic .NET Agent contains SQL Injection
Critical
CVE-2017-9246
was published
for
NewRelic.Agent
(NuGet)
May 17, 2022
ChakraCore RCE Vulnerability
Critical
CVE-2017-0223
was published
for
Microsoft.ChakraCore
(NuGet)
May 17, 2022
ChakraCore RCE Vulnerability
Critical
CVE-2017-8658
was published
for
Microsoft.ChakraCore
(NuGet)
May 17, 2022
ChakraCore vulnerable to privilege escalation
Critical
CVE-2017-11767
was published
for
Microsoft.ChakraCore
(NuGet)
May 13, 2022
ChakraCore RCE Vulnerability
Critical
CVE-2018-8500
was published
for
Microsoft.ChakraCore
(NuGet)
May 13, 2022
CefSharp affected by heap buffer overflow in WebP
Critical
GHSA-j646-gj5p-p45g
was published
for
CefSharp.Common
(NuGet)
Sep 21, 2023
AutoUpdater.NET allows XXE
Critical
CVE-2019-20627
was published
for
Autoupdater.NET.Official
(NuGet)
May 24, 2022
Improper Input Validation in IpMatcher
Critical
CVE-2021-33318
was published
for
IpMatcher
(NuGet)
May 17, 2022
QuantConnect Lean vulnerable to insecure deserialization
Critical
CVE-2020-20136
was published
for
QuantConnect.Common
(NuGet)
May 24, 2022
Duplicate Advisory: tgstation-server vulnerable to cached user logins in legacy server
Critical
GHSA-7r36-jf3c-jhp4
was published
for
TGServiceInterface
(NuGet)
May 13, 2022
•
withdrawn
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
Critical
CVE-2022-39256
was published
for
CompositeC1.Core
(NuGet)
Sep 30, 2022
LiteDB may deserialize bad JSON on object type using _type
Critical
CVE-2022-23535
was published
for
LiteDB
(NuGet)
Feb 24, 2023
ProTip!
Advisories are also available from the
GraphQL API