GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            760 advisories
        Filter by severity
        
      
      
    
                    
                      Duplicate Advisory: .NET and Visual Studio Remote Code Execution Vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-8rxm-6783-qh55
                      
                      was published
                        for
                        
                          System.Formats.Nrbf
                        
                        (NuGet)
                      Nov 12, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: .NET and Visual Studio Denial of Service Vulnerability
                    
                      
  High
                    
                
                      
                        GHSA-wmm6-pgp8-29hg
                      
                      was published
                        for
                        
                          System.Formats.Nrbf
                        
                        (NuGet)
                      Nov 12, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      HTTP Client uses incorrect token after refresh
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-51987
                      
                      was published
                        for
                        
                          Duende.AccessTokenManagement.OpenIdConnect
                        
                        (NuGet)
                      Nov 7, 2024 
                    
                  
                    
                      CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes 
                    
                      
  Critical
                    
                
                      
                        CVE-2024-51501
                      
                      was published
                        for
                        
                          Refit
                        
                        (NuGet)
                      Nov 4, 2024 
                    
                  
                    
                      Duplicate Advisory: Umbraco CMS Cross-site Scripting vulnerability
                    
                      
  Low
                    
                
                      
                        GHSA-4gmq-m9vp-jrwg
                      
                      was published
                        for
                        
                          Umbraco.Cms.Core
                        
                        (NuGet)
                      Nov 4, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Apache Lucene.Net.Replicator Deserialization of Untrusted Data vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-43383
                      
                      was published
                        for
                        
                          Lucene.Net.Replicator
                        
                        (NuGet)
                      Oct 31, 2024 
                    
                  
                    
                      ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-50353
                      
                      was published
                        for
                        
                          ICG.AspNetCore.Utilities.CloudStorage
                        
                        (NuGet)
                      Oct 30, 2024 
                    
                  
                    
                      Duende IdentityServer has insufficient validation of DPoP cnf claim in Local APIs 
                    
                      
  Low
                    
                
                      
                        CVE-2024-49755
                      
                      was published
                        for
                        
                          Duende.IdentityServer
                        
                        (NuGet)
                      Oct 28, 2024 
                    
                  
                    
                      MPXJ has a Potential Path Traversal Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-49771
                      
                      was published
                        for
                        
                          MPXJ.Net
                        
                        (RubyGems)
                      Oct 28, 2024 
                    
                  
                    
                      Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-48929
                      
                      was published
                        for
                        
                          Umbraco.CMS
                        
                        (NuGet)
                      Oct 22, 2024 
                    
                  
                    
                      Umbraco has a Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-48927
                      
                      was published
                        for
                        
                          Umbraco.Cms
                        
                        (NuGet)
                      Oct 22, 2024 
                    
                  
                    
                      Umbraco CMS logout page displayed before session expiration
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-48926
                      
                      was published
                        for
                        
                          Umbraco.CMS
                        
                        (NuGet)
                      Oct 22, 2024 
                    
                  
                    
                      Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
                    
                      
  Low
                    
                
                      
                        CVE-2024-48925
                      
                      was published
                        for
                        
                          Umbraco.CMS
                        
                        (NuGet)
                      Oct 22, 2024 
                    
                  
                    
                      Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-47819
                      
                      was published
                        for
                        
                          @umbraco-cms/backoffice
                        
                        (npm)
                      Oct 22, 2024 
                    
                  
                    
                      Security Update for the OPC UA .NET Standard Stack
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-45526
                      
                      was published
                        for
                        
                          OPCFoundation.NetStandard.Opc.Ua
                        
                        (NuGet)
                      Oct 18, 2024 
                    
                  
                    
                      Security Update for the OPC UA .NET Standard Stack
                    
                      
  High
                    
                
                      
                        GHSA-qm9f-c3v9-wphv
                      
                      was published
                        for
                        
                          OPCFoundation.NetStandard.Opc.Ua
                        
                        (NuGet)
                      Oct 18, 2024 
                    
                  
                    
                      MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-48924
                      
                      was published
                        for
                        
                          MessagePack
                        
                        (NuGet)
                      Oct 17, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-43485
                      
                      was published
                        for
                        
                          System.Text.Json
                        
                        (NuGet)
                      Oct 8, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-43484 | .NET Denial of Service Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-43484
                      
                      was published
                        for
                        
                          System.IO.Packaging
                        
                        (NuGet)
                      Oct 8, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-43483 | .NET Denial of Service Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-43483
                      
                      was published
                        for
                        
                          Microsoft.Extensions.Caching.Memory
                        
                        (NuGet)
                      Oct 8, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-38229 | .NET Remote Code Execution Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-38229
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Oct 8, 2024 
                    
                  
                    
                      CRLF Injection in RestSharp's `RestRequest.AddHeader` method
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-45302
                      
                      was published
                        for
                        
                          RestSharp
                        
                        (NuGet)
                      Aug 29, 2024 
                    
                  
                    
                      Serilog Client IP Spoofing vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-44930
                      
                      was published
                        for
                        
                          Serilog.Enrichers.ClientInfo
                        
                        (NuGet)
                      Aug 29, 2024 
                    
                  
                    
                      Umbraco CMS Improper Access Control vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43377
                      
                      was published
                        for
                        
                          Umbraco.Cms
                        
                        (NuGet)
                      Aug 20, 2024 
                    
                  
                    
                      Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43376
                      
                      was published
                        for
                        
                          Umbraco.Cms.Api.Management
                        
                        (NuGet)
                      Aug 20, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API