NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24836HighDotNetNuke.Core: DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotesCVE-2026-24784MediumDotNetNuke.Core: DotNetNuke.Core has a potential XSS vulnerability in modules' header and footerGHSA-7JXJ-RPX7-PH2CLowUmbraco.Forms: Umbraco.Forms CDN may cache sensitive form uploads when processed by ImageSharpCVE-2026-23952MediumMagick.NET-Q8-x64: ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image loadGHSA-QP59-X883-77QVMediumMagick.NET-Q8-x64: ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XMLCVE-2026-23874MediumMagick.NET-Q8-x64: ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScriptCVE-2026-22770MediumMagick.NET-Q8-x64: ImageMagick releases an invalid pointer in BilateralBlur when memory allocation failsCVE-2021-47776MediumUmbracoCms: Umbraco CMS contains a server-side request forgery vulnerabilityCVE-2025-68924CriticalUmbracoForms: UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client GenerationCVE-2026-22611LowAWSSDK.Core: AWS SDK for .NET V4 adopted defense in depth enhancement for region parameter valueCVE-2025-68950MediumMagick.NET-Q16-AnyCPU: ImageMagick's failure to limit MVG mutual causes Stack OverflowCVE-2025-68618MediumMagick.NET-Q16-AnyCPU: ImageMagick's failure to limit the depth of SVG file reads caused a DoS attackCVE-2025-67290LowPiranha: Piranha has stored cross-site scripting (XSS) vulnerabilityCVE-2025-67288MediumUmbraco.Cms: Umbraco CMS has an arbitrary file upload vulnerabilityCVE-2025-67291LowPiranha: Piranha has stored cross-site scripting (XSS) vulnerabilityCVE-2025-14759MediumAmazon.Extensions.S3.Encryption: Amazon S3 Encryption Client for .NET has a Key Commitment IssueCVE-2025-65581MediumVolo.Abp.Account.Web: ABP Account Module has an Open Redirect through Improper validation in its register functionCVE-2025-66628HighMagick.NET-Q16-AnyCPU: ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)CVE-2025-66625MediumUmbraco.Cms: Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import FunctionalityCVE-2025-66631HighCsla: Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)CVE-2025-64095CriticalDNN.PLATFORM: DNN Insufficient Access Control - Image Upload allows for Site Content OverwriteCVE-2025-64094MediumDotNetNuke.Core: DNN vulnerable to stored cross-site-scripting (XSS) via SVG uploadCVE-2025-62802MediumDnn.Platform: DNN CKEditor Provider allows unauthenticated upload out-of-the-boxCVE-2025-62171MediumMagick.NET-Q16-AnyCPU: ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)CVE-2025-62594MediumMagick.NET-Q16-x64: ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

Stop the waste.
Protect your environment with Kodem.