Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2248575
AlmaLinux
5967
Alpaquita
16105
Alpine
4608
Android
2912
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9341
Chainguard
1030980
CleanStart
3946
CRAN
14
crates.io
2739
Debian
68598
Docker Hardened Images
1
Echo
4006
GHC
3
GIT
107112
GitHub Actions
55
Go
9247
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6232
Maven
7044
MinimOS
144994
npm
228917
NuGet
1869
opam
29
openEuler
8800
openSUSE
14484
OSS-Fuzz
4003
Packagist
7104
Pub
11
PyPI
25200
Red Hat
23387
Rocky Linux
4308
Root
19598
RubyGems
5326
SUSE
23349
SwiftURL
60
TuxCare
9676
Ubuntu
65637
VSCode
21
Wolfi
333108
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wrvw-254r-wpmv
NuGet/AlastairLundy.CliInvoke.Specializations
NuGet/CliInvoke.Specializations
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
4 days ago
Fix available
Severity - 8.4 (High)
GHSA-j73w-8hfr-4gc9
NuGet/AlastairLundy.CliInvoke
NuGet/CliInvoke
CliInvoke: Argument Injection in Extensibility Runner Factory
4 days ago
Fix available
Severity - 8.4 (High)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
22 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
22 Sep
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
22 Sep
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
22 Sep
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
22 Sep
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
22 Sep
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
22 Sep
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
NuGet - OSV