GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
57 advisories
Filter by severity
Defense in Depth update for NuGet Client
Low
GHSA-g4vj-cjjj-v7hg
was published
for
NuGet.CommandLine
(NuGet)
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
GHSA-fcpv-w245-r2q7
was published
for
DotNetNuke.Core
(NuGet)
Apr 14, 2026
ImageMagick has a memory leak in PNG encoder when writing a MNG image
Low
GHSA-x928-4434-crqj
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
Low
GHSA-pmpg-6pww-fg6q
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap buffer overflow read in magnify operation via unrecognized magnify:method value
Low
GHSA-8vfj-q2cp-5m5j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing
Low
GHSA-q8h3-jv9v-57qx
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap-buffer-overflow in FTXT encoder
Low
GHSA-w54j-7wpm-crhj
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
Low
CVE-2026-32178
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Apr 14, 2026
DNN: Same HostGUID for all new installs
Low
CVE-2026-40306
was published
for
DotNetNuke.Core
(NuGet)
Apr 10, 2026
ImageMagick: META reader memory leak in the APP1JPEG input path
Low
GHSA-9r56-3gjq-hqf7
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
ImageMagick has possible memory leak in ASHLAR coder when action fails
Low
GHSA-6p22-q7w5-33pg
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
Duplicate Advisory: OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
GHSA-vmvw-pwwf-cc2w
was published
for
openclaw
(NuGet)
Mar 21, 2026
•
withdrawn
ImageMagick: Heap-based Buffer Overflow in GetPixelIndex due to metadata-cache desynchronization
Low
GHSA-gq5v-qf8q-fp77
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Memory Leak in multiple coders that write raw pixel data
Low
GHSA-wfx3-6g53-9fgc
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Memory leak in coders/txt.c without freetype
Low
GHSA-3q5f-gmjc-38r8
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-xpg8-7m6m-jf56
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS
Low
GHSA-wgxp-q8xq-wpp9
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
mageMagick has a possible use-after-free write in its PDB decoder
Low
GHSA-3j4x-rwrx-xxj9
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Low
GHSA-2gq3-ww97-wfjm
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds
Low
CVE-2026-25984
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Umbraco.Forms CDN may cache sensitive form uploads when processed by ImageSharp
Low
GHSA-7jxj-rpx7-ph2c
was published
for
Umbraco.Forms
(NuGet)
Jan 22, 2026
AWS SDK for .NET V4 adopted defense in depth enhancement for region parameter value
Low
CVE-2026-22611
was published
for
AWSSDK.Core
(NuGet)
Jan 9, 2026
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67290
was published
for
Piranha
(NuGet)
Dec 22, 2025
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67291
was published
for
Piranha
(NuGet)
Dec 22, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Low
CVE-2025-59546
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
ProTip!
Advisories are also available from the
GraphQL API