GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,058
Maven
5,000+
npm
4,845
NuGet
825
pip
4,397
Pub
12
RubyGems
988
Rust
1,147
Swift
50
Unreviewed advisories
All unreviewed
5,000+
459 advisories
Filter by severity
Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints
High
CVE-2026-27449
was published
for
Umbraco.Engage.Forms
(NuGet)
Feb 27, 2026
ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder
High
CVE-2026-25989
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Stack buffer overflow in FTXT reader via oversized integer field
High
CVE-2026-25967
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Policy bypass through path traversal allows reading restricted content despite secured policy
High
CVE-2026-25965
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions
High
CVE-2026-25794
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Infinite loop vulnerability when parsing a PCD file
High
CVE-2026-24485
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression
High
CVE-2026-24481
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
High
CVE-2026-21218
was published
for
System.Security.Cryptography.Cose
(NuGet)
Feb 10, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
High
CVE-2026-24837
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
High
CVE-2026-24836
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
High
CVE-2025-66628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 10, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
CVE-2025-66631
was published
for
Csla
(NuGet)
Dec 8, 2025
Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
High
CVE-2025-55247
was published
for
Microsoft.Build
(NuGet)
Oct 15, 2025
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
High
GHSA-q8g5-rw97-f55h
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
Oct 14, 2025
•
withdrawn
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
High
CVE-2025-57803
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
ImageMagick has a Format String Bug in InterpretImageFilename leads to arbitrary code execution
High
CVE-2025-55298
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
imagemagick: integer overflows in MNG magnification
High
CVE-2025-55154
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
imagemagick: heap-buffer overflow read in MNG magnification with alpha
High
CVE-2025-55004
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has a Stack Buffer Overflow in image.c
High
CVE-2025-53101
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has XMP profile write that triggers hang due to unbounded loop
High
CVE-2025-53015
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 23, 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM possibly allows bypass of IP Filters
High
CVE-2025-52487
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DotVVM allows path traversal when deployed in Debug mode
High
GHSA-6q65-j4jw-9cg8
was published
for
DotVVM
(NuGet)
Jun 19, 2025
ProTip!
Advisories are also available from the
GraphQL API