GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,971
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,091
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
398 advisories
Filter by severity
Duplicate Advisory: Denial of service in CBOR library
High
GHSA-hf3r-vmrv-7w29
was published
for
PeterO.Cbor
(NuGet)
Jan 3, 2024
•
withdrawn
Improper Handling of Exceptional Conditions in Newtonsoft.Json
High
CVE-2024-21907
was published
for
Newtonsoft.Json
(NuGet)
Jun 22, 2022
Duplicate Advisory: Improper Handling of Exceptional Conditions in Newtonsoft.Json
High
GHSA-8rfx-6mr3-5jh3
was published
for
Newtonsoft.Json
(NuGet)
Jan 3, 2024
•
withdrawn
.NET Denial of Service Vulnerability
High
CVE-2022-29145
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Aug 30, 2022
.NET Denial of Service Vulnerability
High
CVE-2022-29117
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Aug 30, 2022
.NET Denial of Service Vulnerability
High
CVE-2022-23267
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Oct 21, 2022
.NET Denial of Service Vulnerability
High
CVE-2022-38013
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Sep 15, 2022
Path Traversal: 'dir/../../filename' in moment.locale
High
CVE-2022-24785
was published
for
Moment.js
(npm)
Apr 4, 2022
Moment.js vulnerable to Inefficient Regular Expression Complexity
High
CVE-2022-31129
was published
for
Moment.js
(npm)
Jul 6, 2022
.NET Remote Code Execution Vulnerability
High
CVE-2023-24895
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Jun 14, 2023
Microsoft Security Advisory CVE-2023-33126: .NET Remote Code Execution Vulnerability
High
CVE-2023-33126
was published
for
Microsoft.NetCore.App.Runtime.win-arm
(NuGet)
Jun 14, 2023
.NET Elevation of Privilege Vulnerability
High
CVE-2023-24936
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jun 14, 2023
Microsoft Security Advisory CVE-2023-36796: .NET Remote Code Execution Vulnerability
High
CVE-2023-36796
was published
for
Microsoft.NETCore.App.Runtime.win-arm64
(NuGet)
Sep 12, 2023
Microsoft Security Advisory CVE-2023-36792: .NET Remote Code Execution Vulnerability
High
CVE-2023-36792
was published
for
Microsoft.NETCore.App.Runtime.win-arm64
(NuGet)
Sep 12, 2023
Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability
High
CVE-2023-36794
was published
for
Microsoft.NETCore.App.Runtime.win-arm64
(NuGet)
Sep 12, 2023
Microsoft Security Advisory CVE-2023-36793: .NET Remote Code Execution Vulnerability
High
CVE-2023-36793
was published
for
Microsoft.NETCore.App.Runtime.win-arm64
(NuGet)
Sep 12, 2023
ChakraCore RCE Vulnerability
High
CVE-2016-3386
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
High
CVE-2023-41890
was published
for
Sustainsys.Saml2
(NuGet)
Sep 20, 2023
Duplicate Advisory: .NET Framework Remote Code Execution Vulnerability.
High
GHSA-9qcm-fqj9-93m4
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-x64
(NuGet)
Dec 13, 2022
•
withdrawn
Directory traversal + file write causing arbitrary code execution
High
CVE-2023-30626
was published
for
Jellyfin.Controller
(NuGet)
Apr 24, 2023
Snowflake Connector .Net Command Injection
High
CVE-2023-34230
was published
for
Snowflake.Data
(NuGet)
Jun 9, 2023
.NET Information Disclosure Vulnerability
High
CVE-2023-35391
was published
for
Microsoft.AspNetCore.SignalR.Redis
(NuGet)
Aug 11, 2023
Insufficient token expiration in Serenity
High
CVE-2023-31287
was published
for
Serenity.Net.Core
(NuGet)
Apr 27, 2023
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
High
CVE-2023-37267
was published
for
Umbraco.Cms.Infrastructure
(NuGet)
Jul 13, 2023
ProTip!
Advisories are also available from the
GraphQL API