Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7952-gx68-cjqr
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: XXE Vulnerability in MerlinReader yesterday
  • Fix available
  • Severity - 7.5 (High)
MAL-2026-16544
  • NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet) yesterday
  • No fix available
MAL-2026-16488
  • NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet) yesterday
  • No fix available
MAL-2026-16489
  • NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet) yesterday
  • No fix available
MAL-2026-16543
  • NuGet/dip.ioc
Malicious code in dip.ioc (NuGet) yesterday
  • No fix available
MAL-2026-16487
  • NuGet/dip.api
Malicious code in dip.api (NuGet) yesterday
  • No fix available
GHSA-5mq7-rwhj-4fh9
  • NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession 6 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
  • NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
  • NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
  • NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
  • NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
  • NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion 6 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
  • NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals 6 days ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-v8pv-4842-x354
  • NuGet/OpenTelemetry.Resources.Host
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS 16 Sep
  • Fix available
  • Severity - 7.0 (High)
GHSA-8cp2-47hg-mfgh
  • NuGet/Microsoft.AspNetCore.Server.IISIntegration
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability 09 Sep
  • Fix available
  • Severity - 5.9 (Medium)