GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,950
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,603
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,250
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      755
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,013
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,048
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            53 advisories
        Filter by severity
        
      
      
    
                    
                      Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54539
                      
                      was published
                        for
                        
                          Apache.NMS.AMQP
                        
                        (NuGet)
                      Oct 16, 2025 
                    
                  
                    
                      Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55315
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Oct 14, 2025 
                    
                  
                    
                      Akka.Remote TLS did not properly implement certificate-based authentication
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61778
                      
                      was published
                        for
                        
                          Akka.Cluster
                        
                        (NuGet)
                      Oct 7, 2025 
                    
                  
                    
                      DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59545
                      
                      was published
                        for
                        
                          DotNetNuke.Core
                        
                        (NuGet)
                      Sep 23, 2025 
                    
                  
                    
                      YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
                    
                      
  Critical
                    
                
                      
                        CVE-2025-43858
                      
                      was published
                        for
                        
                          YoutubeDLSharp
                        
                        (NuGet)
                      Apr 23, 2025 
                    
                  
                    
                      Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-29953
                      
                      was published
                        for
                        
                          Apache.NMS.ActiveMQ
                        
                        (NuGet)
                      Apr 18, 2025 
                    
                  
                    
                      AspNetCore Remote Authenticator for CIE3.0 Allows SAML Response Signature Verification Bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24895
                      
                      was published
                        for
                        
                          CIE.AspNetCore.Authentication
                        
                        (NuGet)
                      Feb 18, 2025 
                    
                  
                    
                      The AspNetCore Remote Authenticator for SPID Allows SAML Response Signature Verification Bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24894
                      
                      was published
                        for
                        
                          SPID.AspNetCore.Authentication
                        
                        (NuGet)
                      Feb 18, 2025 
                    
                  
                    
                      .NET Remote Code Execution Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-43498
                      
                      was published
                        for
                        
                          System.Formats.Nrbf
                        
                        (NuGet)
                      Nov 12, 2024 
                    
                  
                    
                      Duplicate Advisory: .NET and Visual Studio Remote Code Execution Vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-8rxm-6783-qh55
                      
                      was published
                        for
                        
                          System.Formats.Nrbf
                        
                        (NuGet)
                      Nov 12, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes 
                    
                      
  Critical
                    
                
                      
                        CVE-2024-51501
                      
                      was published
                        for
                        
                          Refit
                        
                        (NuGet)
                      Nov 4, 2024 
                    
                  
                    
                      CLSA Directory Traversal vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-28698
                      
                      was published
                        for
                        
                          Csla
                        
                        (NuGet)
                      Jul 22, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-35264
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Jul 9, 2024 
                    
                  
                    
                      NuGet Client Security Feature Bypass Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2024-0057
                      
                      was published
                        for
                        
                          NuGet.CommandLine
                        
                        (NuGet)
                      Feb 13, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-21386
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Feb 13, 2024 
                    
                  
                    
                      Duplicate Advisory: NuGet Client Security Feature Bypass Vulnerability  
                    
                      
  Critical
                    
                
                      
                        GHSA-jw42-5m4v-9c8g
                      
                      was published
                        for
                        
                          NuGet.CommandLine
                        
                        (NuGet)
                      Jan 9, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      CefSharp affected by heap buffer overflow in WebP
                    
                      
  Critical
                    
                
                      
                        GHSA-j646-gj5p-p45g
                      
                      was published
                        for
                        
                          CefSharp.Common
                        
                        (NuGet)
                      Sep 21, 2023 
                    
                  
                    
                      Dynamic Linq vulnerable to remote code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2023-32571
                      
                      was published
                        for
                        
                          System.Linq.Dynamic.Core
                        
                        (NuGet)
                      Jun 22, 2023 
                    
                  
                    
                      LiteDB may deserialize bad JSON on object type using _type
                    
                      
  Critical
                    
                
                      
                        CVE-2022-23535
                      
                      was published
                        for
                        
                          LiteDB
                        
                        (NuGet)
                      Feb 24, 2023 
                    
                  
                    
                      DNS NuGet package uses insufficiently random values
                    
                      
  Critical
                    
                
                      
                        CVE-2021-4248
                      
                      was published
                        for
                        
                          DNS
                        
                        (NuGet)
                      Dec 18, 2022 
                    
                  
                    
                      Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
                    
                      
  Critical
                    
                
                      
                        CVE-2022-39256
                      
                      was published
                        for
                        
                          CompositeC1.Core
                        
                        (NuGet)
                      Sep 30, 2022 
                    
                  
                    
                      Use of Hard-coded Credentials in AgileConfig.Client
                    
                      
  Critical
                    
                
                      
                        CVE-2022-35540
                      
                      was published
                        for
                        
                          AgileConfig.Client
                        
                        (NuGet)
                      Aug 19, 2022 
                    
                  
                    
                      .NET Core Remote Code Execution Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2021-24112
                      
                      was published
                        for
                        
                          System.Drawing.Common
                        
                        (NuGet)
                      May 24, 2022 
                    
                  
                    
                      QuantConnect Lean vulnerable to insecure deserialization
                    
                      
  Critical
                    
                
                      
                        CVE-2020-20136
                      
                      was published
                        for
                        
                          QuantConnect.Common
                        
                        (NuGet)
                      May 24, 2022 
                    
                  
                    
                      AutoUpdater.NET allows XXE
                    
                      
  Critical
                    
                
                      
                        CVE-2019-20627
                      
                      was published
                        for
                        
                          Autoupdater.NET.Official
                        
                        (NuGet)
                      May 24, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API