NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68469LowMagick.NET-Q16-AnyCPU: ImageMagick has a heap-buffer-overflowCVE-2025-53019LowMagick.NET-Q16-AnyCPU: ImageMagick has a Memory Leak in magick streamCVE-2025-53014LowMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Overflow in InterpretImageFilenameCVE-2025-53101HighMagick.NET-Q16-AnyCPU: ImageMagick has a Stack Buffer Overflow in image.cCVE-2025-54575MediumSixLabors.ImageSharp: SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension BlocksCVE-2025-54425MediumUmbraco.Cms.Api.Delivery: Umbraco Delivery API allows for cached requests to be returned with an invalid API keyCVE-2025-53015HighMagick.NET-Q8-AnyCPU: ImageMagick has XMP profile write that triggers hang due to unbounded loopCVE-2025-6965HighSQLitePCLRaw.lib.e_sqlite3: SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLiteCVE-2025-49147MediumUmbraco.Cms: Umbraco CMS disclosure of configured password requirements CVE-2025-52488HighDNN.PLATFORM: DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputCVE-2025-52487HighDNN.PLATFORM: DNN.PLATFORM possibly allows bypass of IP FiltersCVE-2025-52485MediumDNN.PLATFORM: DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity FeedCVE-2025-52486MediumDNN.PLATFORM: DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjectsGHSA-6Q65-J4JW-9CG8HighDotVVM: DotVVM allows path traversal when deployed in Debug modeCVE-2025-49015MediumCouchbaseNetClient: Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificatesCVE-2025-30399HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code VulnerabilityCVE-2025-48953MediumUmbraco.Cms: Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File UploadsCVE-2025-48378MediumDotNetNuke.Core: DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inlineCVE-2025-48377MediumDotNetNuke.Web: Reflected Cross-Site Scripting (XSS) in module actions in edit modeCVE-2025-48376LowDotNetNuke.SiteExportImport: DNN site Import could use an external source with a crafted requestCVE-2025-26646HighMicrosoft.Build.Tasks.Core: Microsoft.Build.Tasks.Core .NET Spoofing VulnerabilityCVE-2025-47280LowUmbraco.Forms: Umbraco.Forms has HTML injection vulnerability in 'Send email' workflowCVE-2025-46736MediumUmbraco.Cms: Umbraco Makes User Enumeration Feasible Based on Timing of Login ResponseCVE-2025-46326LowSnowflake.Data: Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration fileCVE-2025-43858CriticalYoutubeDLSharp: YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

Stop the waste.
Protect your environment with Kodem.