Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2226256
AlmaLinux
5933
Alpaquita
15522
Alpine
4591
Android
2912
Azure Linux
17166
BellSoft Hardened Containers
744
Bitnami
9243
Chainguard
1021600
CleanStart
3506
CRAN
14
crates.io
2728
Debian
67586
Docker Hardened Images
1
Echo
2840
GHC
3
GIT
105032
GitHub Actions
55
Go
9196
Hackage
32
Hex
354
Julia
1713
Linux
28753
Mageia
6216
Maven
7008
MinimOS
143251
npm
228688
NuGet
1867
opam
29
openEuler
8674
openSUSE
14364
OSS-Fuzz
4003
Packagist
7087
Pub
11
PyPI
25131
Red Hat
23271
Rocky Linux
4271
Root
19515
RubyGems
5325
SUSE
23071
SwiftURL
60
TuxCare
9548
Ubuntu
64631
VSCode
21
Wolfi
330690
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
yesterday
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
yesterday
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
yesterday
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
yesterday
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
yesterday
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
yesterday
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
6 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
6 days ago
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
6 days ago
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
6 days ago
Fix available
Severity - 9.1 (Critical)
GHSA-v8pv-4842-x354
NuGet/OpenTelemetry.Resources.Host
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
16 Sep
Fix available
Severity - 7.0 (High)
GHSA-8cp2-47hg-mfgh
NuGet/Microsoft.AspNetCore.Server.IISIntegration
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
09 Sep
Fix available
Severity - 5.9 (Medium)
Load more...
NuGet - OSV