GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
449 advisories
Filter by severity
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
High
CVE-2026-24837
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
High
CVE-2026-24836
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
ImageMagick has a Format String Bug in InterpretImageFilename leads to arbitrary code execution
High
CVE-2025-55298
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
High
CVE-2025-66628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 10, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
CVE-2025-66631
was published
for
Csla
(NuGet)
Dec 8, 2025
Microsoft Security Advisory CVE-2024-38081 | .NET Elevation of Privilege Vulnerability
High
CVE-2024-38081
was published
for
Microsoft.IO.Redist
(NuGet)
Jul 9, 2024
Moment.js vulnerable to Inefficient Regular Expression Complexity
High
CVE-2022-31129
was published
for
Moment.js
(npm)
Jul 6, 2022
Path Traversal: 'dir/../../filename' in moment.locale
High
CVE-2022-24785
was published
for
Moment.js
(npm)
Apr 4, 2022
imagemagick: integer overflows in MNG magnification
High
CVE-2025-55154
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
High
CVE-2025-57803
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
ImageMagick has a Stack Buffer Overflow in image.c
High
CVE-2025-53101
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
High
CVE-2025-55247
was published
for
Microsoft.Build
(NuGet)
Oct 15, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
.NET Denial of Service Vulnerability
High
CVE-2023-38180
was published
for
Microsoft.AspNetCore.App.Runtime.win-arm64
(NuGet)
Aug 9, 2023
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
High
CVE-2020-1147
was published
for
Microsoft.NETCore.App
(NuGet)
May 24, 2022
Inadequate Encryption Strength in DotNetNuke
High
CVE-2018-18325
was published
for
DotNetNuke.Core
(NuGet)
Jul 5, 2019
Inadequate Encryption Strength in DotNetNuke
High
CVE-2018-15811
was published
for
DotNetNuke.Core
(NuGet)
Jul 5, 2019
ChakraCore RCE Vulnerability
High
CVE-2018-8298
was published
for
Microsoft.ChakraCore
(NuGet)
May 13, 2022
ChakraCore RCE Vulnerability
High
CVE-2016-7200
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
ChakraCore RCE Vulnerability
High
CVE-2016-7201
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
High
GHSA-q8g5-rw97-f55h
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
Oct 14, 2025
•
withdrawn
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
PowerShell Elevation of Privilege Vulnerability
High
CVE-2022-26788
was published
for
Microsoft.PowerShell.SDK
(NuGet)
Apr 16, 2022
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API