GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
217 advisories
Filter by severity
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
Moderate
CVE-2025-59821
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
Moderate
CVE-2025-59539
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Moderate
CVE-2025-9708
was published
for
KubernetesClient
(NuGet)
Sep 17, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
ImageMagick has Undefined Behavior (function-type-mismatch) in CloneSplayTree
Moderate
CVE-2025-55160
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
Moderate
CVE-2025-54575
was published
for
SixLabors.ImageSharp
(NuGet)
Jul 30, 2025
Umbraco Delivery API allows for cached requests to be returned with an invalid API key
Moderate
CVE-2025-54425
was published
for
Umbraco.Cms.Api.Delivery
(NuGet)
Jul 29, 2025
Umbraco CMS disclosure of configured password requirements
Moderate
CVE-2025-49147
was published
for
Umbraco.Cms
(NuGet)
Jun 24, 2025
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate
CVE-2025-52485
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Moderate
CVE-2025-52486
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
Moderate
CVE-2025-49015
was published
for
CouchbaseNetClient
(NuGet)
Jun 18, 2025
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Moderate
CVE-2025-48953
was published
for
Umbraco.Cms
(NuGet)
Jun 4, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Moderate
CVE-2025-48378
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Moderate
CVE-2025-48377
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Moderate
CVE-2025-46736
was published
for
Umbraco.Cms
(NuGet)
May 6, 2025
Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs
Moderate
CVE-2025-32016
was published
for
Microsoft.Identity.Abstractions
(NuGet)
Apr 9, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-32372
was published
for
DotNetNuke.Core
(NuGet)
Apr 9, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Moderate
CVE-2025-27602
was published
for
Umbraco.Cms.Web.Backoffice
(NuGet)
Mar 11, 2025
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Moderate
CVE-2025-27601
was published
for
Umbraco.Cms.Api.Management
(NuGet)
Mar 11, 2025
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
Moderate
CVE-2025-27513
was published
for
OpenTelemetry.Api
(NuGet)
Mar 5, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42512
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
Mar 3, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua.Bindings.Https
(NuGet)
Mar 3, 2025
AutoQueryable leaks sensitive information
Moderate
CVE-2024-57716
was published
for
AutoQueryable
(NuGet)
Feb 20, 2025
Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credentials Access Tokens
Moderate
CVE-2025-26620
was published
for
Duende.AccessTokenManagement
(NuGet)
Feb 19, 2025
ProTip!
Advisories are also available from the
GraphQL API