Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,131 advisories

Loading
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers High
CVE-2026-100368 was published for AlastairLundy.CliInvoke.Specializations (NuGet) Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory High
CVE-2026-100369 was published for AlastairLundy.CliInvoke (NuGet) Sep 25, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c Low
CVE-2026-56379 was published for Magick.NET-Q16-AnyCPU (NuGet) Feb 25, 2026
phenggeler Credited to phenggeler
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c Low
GHSA-v772-658q-978p was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 23, 2026 • withdrawn
ImageMagick has a possible heap Use After Free vulnerability in its meta coder Low
CVE-2026-56376 was published for Magick.NET-Q16-AnyCPU (NuGet) Feb 25, 2026
ylwango613 Credited to ylwango613
Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder Moderate
GHSA-8g9f-ccmr-vfvg was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 23, 2026 • withdrawn
ImageMagick: Memory leak in coders/txt.c without freetype Low
CVE-2026-56371 was published for Magick.NET-Q16-AnyCPU (NuGet) Feb 25, 2026
unbengable12 Credited to unbengable12
Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype Low
GHSA-98gv-6gmj-cm6m was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 23, 2026 • withdrawn
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
MPXJ: XXE Vulnerability in MerlinReader High
CVE-2026-61570 was published for MPXJ.Net (RubyGems) Sep 22, 2026
dyingman1 Credited to dyingman1
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts Low
CVE-2026-56370 was published for Magick.NET-Q16-AnyCPU (NuGet) Apr 14, 2026
ylwango613 Credited to ylwango613
Steeltoe: Header-forwarded client cert lacks proof of private-key possession Moderate
CVE-2026-81868 was published for Steeltoe.Security.Authorization.Certificate (NuGet) Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) High
CVE-2026-81516 was published for Steeltoe.Discovery.Consul (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) High
CVE-2026-81515 was published for Steeltoe.Discovery.Eureka (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Moderate
CVE-2026-75523 was published for Steeltoe.Management.Endpoint (NuGet) Sep 17, 2026
manus-use Credited to manus-use
SSH.NET: ScpClient allows server-side RCE via default SCP path handling High
CVE-2026-85756 was published for SSH.NET (NuGet) Sep 17, 2026
Nadav0077 Credited to Nadav0077
suryadina Credited to suryadina
Marten's LINQ provider has SQL injection via unescaped string literals Critical
CVE-2026-75513 was published for Marten (NuGet) Sep 17, 2026
svenclaesson Credited to svenclaesson
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS High
CVE-2026-81192 was published for OpenTelemetry.Resources.Host (NuGet) Sep 16, 2026
martincostello Credited to martincostello and lachmatt lachmatt lachmatt
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability Moderate
CVE-2026-69304 was published for Microsoft.AspNetCore.Server.IISIntegration (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-69522 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
CVE-2026-69439 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
GHSA-mqvm-gmc4-6rv2 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-71328 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
GHSA-4qhr-qf46-fcrx was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
ProTip! Advisories are also available from the GraphQL API