Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,134 advisories

Loading
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests Low
CVE-2026-105795 was published for Microsoft.OpenApi.Kiota (NuGet) Oct 6, 2026
gavinbarron Credited to gavinbarron and adrian05-ms adrian05-ms adrian05-ms
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators High
CVE-2026-105796 was published for Microsoft.OpenApi.Kiota (NuGet) Oct 6, 2026
gavinbarron Credited to gavinbarron
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL Critical
CVE-2026-105794 was published for Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet) Oct 6, 2026
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers High
CVE-2026-100368 was published for AlastairLundy.CliInvoke.Specializations (NuGet) Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory High
CVE-2026-100369 was published for AlastairLundy.CliInvoke (NuGet) Sep 25, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
MPXJ: XXE Vulnerability in MerlinReader High
CVE-2026-61570 was published for MPXJ.Net (RubyGems) Sep 22, 2026
dyingman1 Credited to dyingman1
Steeltoe: Header-forwarded client cert lacks proof of private-key possession Moderate
CVE-2026-81868 was published for Steeltoe.Security.Authorization.Certificate (NuGet) Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) High
CVE-2026-81516 was published for Steeltoe.Discovery.Consul (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) High
CVE-2026-81515 was published for Steeltoe.Discovery.Eureka (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Moderate
CVE-2026-75523 was published for Steeltoe.Management.Endpoint (NuGet) Sep 17, 2026
manus-use Credited to manus-use
SSH.NET: ScpClient allows server-side RCE via default SCP path handling High
CVE-2026-85756 was published for SSH.NET (NuGet) Sep 17, 2026
Nadav0077 Credited to Nadav0077
suryadina Credited to suryadina
Marten's LINQ provider has SQL injection via unescaped string literals Critical
CVE-2026-75513 was published for Marten (NuGet) Sep 17, 2026
svenclaesson Credited to svenclaesson
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS High
CVE-2026-81192 was published for OpenTelemetry.Resources.Host (NuGet) Sep 16, 2026
martincostello Credited to martincostello and lachmatt lachmatt lachmatt
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability Moderate
CVE-2026-69304 was published for Microsoft.AspNetCore.Server.IISIntegration (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-69522 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
CVE-2026-69439 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-71328 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability High
CVE-2026-50646 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Sep 8, 2026
Microsoft QUIC: Remote Code Execution Vulnerability Critical
CVE-2026-62815 was published for Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet) Sep 8, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62900 was published for Microsoft.Build.Tasks.Git (NuGet) Sep 8, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability High
GHSA-4qhr-qf46-fcrx was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
GHSA-q72m-f2r4-w4cw was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability High
GHSA-mqvm-gmc4-6rv2 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 8, 2026 • withdrawn
ProTip! Advisories are also available from the GraphQL API