Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2238494
AlmaLinux
5967
Alpaquita
16148
Alpine
4635
Android
3677
Azure Linux
17767
BellSoft Hardened Containers
764
Bitnami
9476
Chainguard
1047166
CleanStart
5235
CRAN
14
crates.io
2761
Debian
68903
Echo
7751
GHC
3
GIT
108757
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148075
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14540
OSS-Fuzz
4015
Packagist
7101
Pub
11
PyPI
25450
Red Hat
23506
Rocky Linux
4339
Root
19620
RubyGems
5327
SUSE
23440
SwiftURL
60
TuxCare
9847
Ubuntu
65983
VSCode
21
Wolfi
293480
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wrvw-254r-wpmv
NuGet/AlastairLundy.CliInvoke.Specializations
NuGet/CliInvoke.Specializations
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
25 Sep
Fix available
Severity - 8.4 (High)
GHSA-j73w-8hfr-4gc9
NuGet/AlastairLundy.CliInvoke
NuGet/CliInvoke
CliInvoke: Argument Injection in Extensibility Runner Factory
25 Sep
Fix available
Severity - 8.4 (High)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
22 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
22 Sep
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
22 Sep
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
22 Sep
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
22 Sep
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
22 Sep
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
22 Sep
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
NuGet - OSV