Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2309270
AlmaLinux
6003
Alpaquita
16176
Alpine
4655
Android
2912
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9517
Chainguard
1048720
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68982
Docker Hardened Images
1
Echo
4008
GHC
3
GIT
107838
GitHub Actions
55
Go
9334
Hackage
33
Hex
365
Julia
1713
Linux
29270
Mageia
6237
Maven
7055
MinimOS
148534
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14651
OSS-Fuzz
4003
Packagist
7109
Pub
11
PyPI
25490
Red Hat
23535
Rocky Linux
4344
Root
19651
RubyGems
5369
SUSE
23454
SwiftURL
61
TuxCare
9676
Ubuntu
66099
VSCode
21
Wolfi
337047
WordPress
30313
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wrvw-254r-wpmv
NuGet/AlastairLundy.CliInvoke.Specializations
NuGet/CliInvoke.Specializations
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
25 Sep
Fix available
Severity - 8.4 (High)
GHSA-j73w-8hfr-4gc9
NuGet/AlastairLundy.CliInvoke
NuGet/CliInvoke
CliInvoke: Argument Injection in Extensibility Runner Factory
25 Sep
Fix available
Severity - 8.4 (High)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
22 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
22 Sep
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
22 Sep
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
22 Sep
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
22 Sep
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
22 Sep
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
22 Sep
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
NuGet - OSV