Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2257314
AlmaLinux
5974
Alpaquita
16124
Alpine
4618
Android
2912
Azure Linux
17673
BellSoft Hardened Containers
762
Bitnami
9341
Chainguard
1035748
CleanStart
4478
CRAN
14
crates.io
2746
Debian
68680
Docker Hardened Images
1
Echo
4006
GHC
3
GIT
107282
GitHub Actions
55
Go
9249
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6233
Maven
7046
MinimOS
146638
npm
229024
NuGet
1869
opam
29
openEuler
8900
openSUSE
14502
OSS-Fuzz
4003
Packagist
7106
Pub
11
PyPI
25228
Red Hat
23413
Rocky Linux
4321
Root
19603
RubyGems
5326
SUSE
23389
SwiftURL
60
TuxCare
9676
Ubuntu
65810
VSCode
21
Wolfi
334061
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wrvw-254r-wpmv
NuGet/AlastairLundy.CliInvoke.Specializations
NuGet/CliInvoke.Specializations
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
5 days ago
Fix available
Severity - 8.4 (High)
GHSA-j73w-8hfr-4gc9
NuGet/AlastairLundy.CliInvoke
NuGet/CliInvoke
CliInvoke: Argument Injection in Extensibility Runner Factory
5 days ago
Fix available
Severity - 8.4 (High)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
22 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
22 Sep
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
22 Sep
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
22 Sep
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
22 Sep
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
22 Sep
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
22 Sep
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
NuGet - OSV