GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,057
Maven
5,000+
npm
3,742
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
417 advisories
Filter by severity
Improper Input Validation in Microsoft.NETCore.App
High
CVE-2017-8585
was published
for
Microsoft.NETCore.App
(NuGet)
May 17, 2022
.NET Core Denial of Service Vulnerability
High
CVE-2018-0875
was published
for
Microsoft.NETCore.Jit
(NuGet)
May 13, 2022
Missing Authorization with Default Settings in Dashboard UI
High
CVE-2021-41238
was published
for
Hangfire.Core
(NuGet)
Nov 3, 2021
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
High
CVE-2018-8409
was published
for
Microsoft.AspNetCore.All
(NuGet)
Oct 16, 2018
Improper Certificate Validation in Microsoft .NET Framework components
High
CVE-2018-0786
was published
for
Microsoft.NETCore.UniversalWindowsPlatform
(NuGet)
Oct 16, 2018
Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption
High
CVE-2021-42279
was published
for
Microsoft.ChakraCore
(NuGet)
May 24, 2022
Incorrect Access Control and Cross Site Scripting in Jellyfin
High
CVE-2022-35909
was published
for
Jellyfin.Common
(NuGet)
Aug 20, 2022
Denial of service in ASP.NET Core
High
CVE-2019-0982
was published
for
Microsoft.AspNetCore.SignalR.Protocols.MessagePack
(NuGet)
May 24, 2022
Exposure of Sensitive Information in System.Net.Http
High
CVE-2019-0545
was published
for
Microsoft.NETCore.App
(NuGet)
May 14, 2022
Denial of service in ASP.NET Core
High
CVE-2019-0564
was published
for
Microsoft.AspNetCore.All
(NuGet)
May 14, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
High
CVE-2017-8700
was published
for
Microsoft.AspNetCore.Mvc.Core
(NuGet)
May 13, 2022
Denial of service in ASP.NET Core
High
CVE-2017-11883
was published
for
Microsoft.AspNetCore.Server.HttpSys
(NuGet)
May 13, 2022
Denial of service in ASP.NET Core
High
CVE-2019-0980
was published
for
System.Private.Uri
(NuGet)
May 24, 2022
Denial of service in ASP.NET Core
High
CVE-2019-0981
was published
for
System.Private.Uri
(NuGet)
May 24, 2022
Open redirect in ASP.NET Core
High
CVE-2017-11879
was published
for
Microsoft.AspNetCore.All
(NuGet)
May 14, 2022
YARP Denial of Service Vulnerability
High
CVE-2022-26924
was published
for
Yarp.ReverseProxy
(NuGet)
Apr 22, 2022
Server side request forgery in C1 CMS
High
CVE-2022-24789
was published
for
C1CMS.Assemblies
(NuGet)
Mar 30, 2022
Path traversal in elFinder.NetCore
High
CVE-2021-23428
was published
for
elFinder.NetCore
(NuGet)
Sep 2, 2021
Improper Certificate Validation
High
CVE-2017-11770
was published
for
Microsoft.NETCore.App
(NuGet)
Apr 12, 2022
Infinite loop in .Net Bond
High
CVE-2020-1469
was published
for
Bond.Core.CSharp
(NuGet)
Apr 8, 2022
.NET Core Information Disclosure
High
CVE-2018-8292
was published
for
System.Net.Http
(NuGet)
Apr 21, 2021
Improper Authentication
High
GHSA-qxx8-292g-2w66
was published
for
Microsoft.Bot.Connector
(NuGet)
Mar 8, 2021
ProTip!
Advisories are also available from the
GraphQL API