Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

66 advisories

Loading
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse Critical
GHSA-5wr9-m6jw-xx44 was published for Scriban.Signed (NuGet) Mar 24, 2026
Zwique Credited to Zwique and adamus2 adamus2 adamus2
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation Critical
CVE-2026-54782 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
DotVVM: Missing authorization in AuthorizeActionFilter Critical
GHSA-c8qj-jx8j-fg2w was published for DotVVM (NuGet) Jun 19, 2026
Marten has an injection vulnerability in its full-text search regConfig parameter Critical
CVE-2026-45288 was published for Marten (NuGet) May 14, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability Critical
CVE-2026-32179 was published for Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet) Apr 16, 2026
ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents Critical
CVE-2026-40324 was published for HotChocolate.Language (NuGet) Apr 16, 2026
BZHunt Credited to BZHunt
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege Critical
CVE-2026-40372 was published for Microsoft.AspNetCore.DataProtection (NuGet) Apr 23, 2026
rbhanda Credited to rbhanda
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK Critical
CVE-2026-25592 was published for Microsoft.SemanticKernel.Core (NuGet) Feb 6, 2026
doredry Credited to doredry, amiteliahu, and urioren amiteliahu amiteliahu
urioren urioren
Remote Code Execution in AjaxNetProfessional Critical
CVE-2021-23758 was published for AjaxNetProfessional (NuGet) Dec 7, 2021
h0ng10 Credited to h0ng10 and mwulftange mwulftange mwulftange
Duplicate Advisory: Remote Code Execution in AjaxNetProfessional Critical
GHSA-74r6-grj9-8rq6 was published for AjaxNetProfessional (NuGet) Dec 16, 2021 withdrawn
DotNetNuke.Core Vulnerable to Stored XSS via Module Title Critical
CVE-2026-24838 was published for DotNetNuke.Core (NuGet) Jan 28, 2026
bdukes Credited to bdukes
chudyPB Credited to chudyPB
Withdrawn Advisory: Emby Server API Vulnerability allowing to gain administrative access without precondition Critical
CVE-2025-64113 was published for MediaBrowser.Server.Core (NuGet) Dec 8, 2025 withdrawn
tembybot Credited to tembybot and softworkz softworkz softworkz
Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability Critical
CVE-2025-54539 was published for Apache.NMS.AMQP (NuGet) Oct 16, 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite Critical
CVE-2025-64095 was published for DNN.PLATFORM (NuGet) Oct 29, 2025
bdukes Credited to bdukes and valadas valadas valadas
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability Critical
CVE-2025-55315 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Oct 14, 2025
victorisr Credited to victorisr and udlose udlose udlose
Akka.Remote TLS did not properly implement certificate-based authentication Critical
CVE-2025-61778 was published for Akka.Cluster (NuGet) Oct 7, 2025
Aaronontheweb Credited to Aaronontheweb
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module Critical
CVE-2025-59545 was published for DotNetNuke.Core (NuGet) Sep 23, 2025
bdukes Credited to bdukes, valadas, and mitchelsellers valadas valadas
mitchelsellers mitchelsellers
Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability Critical
CVE-2024-35264 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Jul 9, 2024
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments Critical
CVE-2025-43858 was published for YoutubeDLSharp (NuGet) Apr 23, 2025
kitsumed Credited to kitsumed and alxnull alxnull alxnull
Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability Critical
CVE-2025-29953 was published for Apache.NMS.ActiveMQ (NuGet) Apr 18, 2025
Blogifier does not properly restrict APIs Critical
CVE-2019-12277 was published for Blogifier.Core (NuGet) May 24, 2022
Code injection in RazorEngine Critical
CVE-2021-46703 was published for RazorEngine (NuGet) Mar 7, 2022
skofman1 Credited to skofman1 and malmor malmor malmor
ProTip! Advisories are also available from the GraphQL API