Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2194424
AlmaLinux
5916
Alpaquita
15522
Alpine
4594
Android
3674
Azure Linux
17378
BellSoft Hardened Containers
744
Bitnami
9287
Chainguard
1022897
CleanStart
3529
CRAN
14
crates.io
2730
Debian
68267
Echo
6685
GHC
3
GIT
107272
GitHub Actions
55
Go
9202
Hackage
32
Hex
358
Julia
1713
Linux
29602
Mageia
6224
Maven
7011
MinimOS
143576
npm
228726
NuGet
1867
opam
29
openEuler
8800
openSUSE
14381
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25150
Red Hat
23316
Rocky Linux
4282
Root
19534
RubyGems
5325
SUSE
23078
SwiftURL
60
TuxCare
9422
Ubuntu
64999
VSCode
21
Wolfi
288030
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
2 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
2 days ago
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
3 days ago
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
3 days ago
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
3 days ago
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
3 days ago
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
3 days ago
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
GHSA-v8pv-4842-x354
NuGet/OpenTelemetry.Resources.Host
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
16 Sep
Fix available
Severity - 7.0 (High)
GHSA-8cp2-47hg-mfgh
NuGet/Microsoft.AspNetCore.Server.IISIntegration
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
09 Sep
Fix available
Severity - 5.9 (Medium)
Load more...
NuGet - OSV