Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

394 advisories

Loading
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow Moderate
CVE-2026-53466 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 31, 2026
Bin-infinite Credited to Bin-infinite
kongzhenhit-code Credited to kongzhenhit-code
ImageMagick: Heap Buffer Over-Write in fx operation Moderate
CVE-2026-62363 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Kwstubbs Credited to Kwstubbs
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided Moderate
CVE-2026-62343 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Kwstubbs Credited to Kwstubbs
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
GHSA-p5rm-jg5c-8c77 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron and gn00295120 gn00295120 gn00295120
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219 Moderate
GHSA-56m6-8q75-f2rw was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments Moderate
CVE-2026-55597 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image Moderate
CVE-2026-55510 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Serotav Credited to Serotav
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged Moderate
CVE-2026-53467 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 23, 2026
Serotav Credited to Serotav
SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant) Moderate
CVE-2026-44788 was published for SharpCompress (NuGet) May 8, 2026
svenclaesson Credited to svenclaesson, HackingRepo, and lewishazell HackingRepo HackingRepo
lewishazell lewishazell
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability Moderate
CVE-2026-50659 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass Moderate
CVE-2026-54570 was published for AngleSharp (NuGet) Jul 17, 2026
internetpestcontrol Credited to internetpestcontrol
Umbraco.AI discloses sensitive application configuration values Moderate
GHSA-q3v2-xj35-9grx was published for Umbraco.AI (NuGet) Jul 14, 2026
Potential XSS vulnerability in jQuery Moderate
CVE-2020-11022 was published for athlon1600/youtube-downloader (RubyGems) Apr 29, 2020
masatokinugawa Credited to masatokinugawa, Churro, Rudloff, sealonohana, and Athlon1600 Churro Churro
Rudloff Rudloff sealonohana sealonohana Athlon1600 Athlon1600
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation Moderate
GHSA-xw6w-9jjh-p9cr was published for Scriban (NuGet) Mar 24, 2026
offset Credited to offset and adamus2 adamus2 adamus2
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString Moderate
GHSA-m2p3-hwv5-xpqw was published for Scriban (NuGet) Mar 24, 2026
offset Credited to offset and adamus2 adamus2 adamus2
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service) Moderate
GHSA-5rpf-x9jg-8j5p was published for Scriban.Signed (NuGet) Mar 19, 2026
adamus2 Credited to adamus2
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted Moderate
CVE-2026-50267 was published for Steeltoe.Configuration.Abstractions (NuGet) Jul 2, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated Moderate
CVE-2026-50202 was published for Steeltoe.Security.Authentication.CloudFoundryBase (NuGet) Jul 2, 2026
ProTip! Advisories are also available from the GraphQL API