GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
200 advisories
Filter by severity
Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes
Moderate
CVE-2025-24011
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6531
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
Cross-site Scripting in jquery-ui
Moderate
CVE-2010-5312
was published
for
jQuery.UI.Combined
(RubyGems)
Oct 24, 2017
Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs
Moderate
CVE-2025-32016
was published
for
Microsoft.Identity.Abstractions
(NuGet)
Apr 9, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-32372
was published
for
DotNetNuke.Core
(NuGet)
Apr 9, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Moderate
CVE-2025-27602
was published
for
Umbraco.Cms.Web.Backoffice
(NuGet)
Mar 11, 2025
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Moderate
CVE-2025-27601
was published
for
Umbraco.Cms.Api.Management
(NuGet)
Mar 11, 2025
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
Moderate
CVE-2025-27513
was published
for
OpenTelemetry.Api
(NuGet)
Mar 5, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42512
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
Mar 3, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua.Bindings.Https
(NuGet)
Mar 3, 2025
Duplicate Advisory: Authentication Bypass by Spoofing in OPC UA .NET Standard Stack
Moderate
GHSA-7wwr-h8cm-9jf7
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Feb 10, 2025
•
withdrawn
Potential leak of NuGet.org API key
Moderate
CVE-2022-30184
was published
for
NuGet.CommandLine
(NuGet)
Jun 14, 2022
AutoQueryable leaks sensitive information
Moderate
CVE-2024-57716
was published
for
AutoQueryable
(NuGet)
Feb 20, 2025
XSS/HTML Injection Vulnerability in Umbraco Preview Badge
Moderate
CVE-2024-10761
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credentials Access Tokens
Moderate
CVE-2025-26620
was published
for
Duende.AccessTokenManagement
(NuGet)
Feb 19, 2025
Cross-site Scripting in Serenity
Moderate
CVE-2024-26318
was published
for
@serenity-is/corelib
(npm)
Feb 19, 2024
Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting
Moderate
CVE-2024-55488
was published
for
Umbraco.Cms.Infrastructure
(NuGet)
Jan 22, 2025
•
withdrawn
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Moderate
CVE-2024-35218
was published
for
UmbracoCms.Core
(NuGet)
May 21, 2024
Blind SSRF Leads to Port Scan by using Webhooks
Moderate
CVE-2024-29035
was published
for
Umbraco.Cms.Core
(NuGet)
Apr 17, 2024
TShock allows chat while not fully connected, possible ban evasion
Moderate
GHSA-f8mx-cwfh-7hr2
was published
for
tshock
(NuGet)
Feb 3, 2025
Heap buffer overflow in CefSharp
Moderate
CVE-2020-15999
was published
for
CefSharp.Common
(NuGet)
Oct 27, 2020
User account enumeration in Serenity
Moderate
CVE-2023-31286
was published
for
Serenity.Net.Core
(NuGet)
Apr 27, 2023
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
athlon1600/youtube-downloader
(RubyGems)
Apr 29, 2020
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6484
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
ProTip!
Advisories are also available from the
GraphQL API