NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-61413MediumPiranha: Piranha CMS vulnerable to stored cross-site scripting (XSS)CVE-2025-11849Mediummammoth: Mammoth is vulnerable to Directory TraversalCVE-2025-11842MediumSmidge: Smidge is vulnerable to Path TraversalCVE-2025-54539CriticalApache.NMS.AMQP: Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerabilityCVE-2025-55248MediumMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure VulnerabilityCVE-2025-55247HighMicrosoft.Build.Tasks.Core: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service VulnerabilityCVE-2025-55315CriticalMicrosoft.AspNetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass VulnerabilityCVE-2025-11573HighAmazon.IonDotnet: Amazon.IonDotnet is vulnerable to Denial of Service attacksCVE-2025-61778CriticalAkka.Remote: Akka.Remote TLS did not properly implement certificate-based authenticationCVE-2025-55797MediumFormCMS: FormCMS has an improper access control vulnerability in the /api/schemas/history/[schemaId] endpointCVE-2025-57692MediumPiranha: PiranhaCMS stored XSSCVE-2025-59821MediumDotNetNuke.Core: DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profileCVE-2025-59546LowDotNetNuke.Core: DNN Vulnerable to Stored XSS Using Backend Admin CredentialsCVE-2025-59545CriticalDotNetNuke.Core: DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt moduleCVE-2025-59539MediumDotNetNuke.Core: DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography fieldCVE-2025-59535MediumDotNetNuke.Core: DNN allows loading unused themes on anonymous clients through query parametersCVE-2025-9708MediumKubernetesClient: Kubernetes C# client accepts certificates from any CA without properly verifying the trust chainCVE-2025-57807LowMagick.NET-Q16-x64: ImageMagick BlobStream Forward-Seek Under-AllocationCVE-2025-56236MediumFormCMS: FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerabilityCVE-2025-57803HighMagick.NET-Q16-AnyCPU: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflowCVE-2025-55298HighMagick.NET-Q16-AnyCPU: ImageMagick has a Format String Bug in InterpretImageFilename leads to arbitrary code executionCVE-2025-55212LowMagick.NET-Q16-AnyCPU: ImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crashCVE-2025-55160MediumMagick.NET-Q16-AnyCPU: ImageMagick has Undefined Behavior (function-type-mismatch) in CloneSplayTreeCVE-2025-55154HighMagick.NET-Q8-x86: imagemagick: integer overflows in MNG magnificationCVE-2025-55004HighMagick.NET-Q16-AnyCPU: imagemagick: heap-buffer overflow read in MNG magnification with alpha

Stop the waste.
Protect your environment with Kodem.