Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2269805
AlmaLinux
5993
Alpaquita
16148
Alpine
4635
Android
2912
Azure Linux
17766
BellSoft Hardened Containers
764
Bitnami
9492
Chainguard
1043402
CleanStart
5235
CRAN
14
crates.io
2748
Debian
68814
Docker Hardened Images
1
Echo
4007
GHC
3
GIT
107466
GitHub Actions
55
Go
9321
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6237
Maven
7048
MinimOS
147595
npm
229081
NuGet
1869
opam
29
openEuler
8900
openSUSE
14530
OSS-Fuzz
4003
Packagist
7106
Pub
11
PyPI
25411
Red Hat
23506
Rocky Linux
4338
Root
19620
RubyGems
5326
SUSE
23402
SwiftURL
60
TuxCare
9676
Ubuntu
65819
VSCode
21
Wolfi
336062
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wrvw-254r-wpmv
NuGet/AlastairLundy.CliInvoke.Specializations
NuGet/CliInvoke.Specializations
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
6 days ago
Fix available
Severity - 8.4 (High)
GHSA-j73w-8hfr-4gc9
NuGet/AlastairLundy.CliInvoke
NuGet/CliInvoke
CliInvoke: Argument Injection in Extensibility Runner Factory
6 days ago
Fix available
Severity - 8.4 (High)
GHSA-7952-gx68-cjqr
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
22 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
Maven/net.sf.mpxj:mpxj
NuGet/MPXJ.Net
NuGet/net.sf.mpxj
NuGet/net.sf.mpxj-for-csharp
NuGet/net.sf.mpxj-for-vb
... 2 more
MPXJ: XXE Vulnerability in MerlinReader
22 Sep
Fix available
Severity - 7.5 (High)
MAL-2026-16544
NuGet/dip.ioc.extensions
Malicious code in dip.ioc.extensions (NuGet)
22 Sep
No fix available
MAL-2026-16488
NuGet/dip.infrastructure
Malicious code in dip.infrastructure (NuGet)
22 Sep
No fix available
MAL-2026-16489
NuGet/dip.infrastructure.context
Malicious code in dip.infrastructure.context (NuGet)
22 Sep
No fix available
MAL-2026-16543
NuGet/dip.ioc
Malicious code in dip.ioc (NuGet)
22 Sep
No fix available
MAL-2026-16487
NuGet/dip.api
Malicious code in dip.api (NuGet)
22 Sep
No fix available
GHSA-5mq7-rwhj-4fh9
NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
17 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
17 Sep
Fix available
Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
17 Sep
Fix available
Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
NuGet - OSV