NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-3857HighAmazon.IonDotnet: Infinite loop condition in Amazon.IonDotnetCVE-2025-29953CriticalApache.NMS.ActiveMQ: Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerabilityGHSA-F87W-3J5W-V58PHighCefSharp.Wpf: CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on WindowsCVE-2025-32016MediumMicrosoft.Identity.Web: Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service LogsCVE-2025-32372MediumDotNetNuke.Core: DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)CVE-2025-32017HighUmbraco.Cms: Umbraco has a Management API Vulnerability to Path Traversal With Authenticated UsersCVE-2025-24070HighMicrosoft.AspNetCore.Identity: Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege VulnerabilityCVE-2025-27602MediumUmbraco.Cms.Web.Backoffice: Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized ContentCVE-2025-27601MediumUmbraco.Cms.Api.Management: Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type FunctionalityCVE-2025-24043Highdotnet-sos: Microsoft Security Advisory CVE-2025-24043 | WinDbg Remote Code Execution VulnerabilityGHSA-VC29-VG52-6643HighOpenTelemetry.AutoInstrumentation: DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.ApiCVE-2025-27598HighSixLabors.ImageSharp: Out-of-bounds Write in SixLabors ImageSharpCVE-2025-27513MediumOpenTelemetry.Api: OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API PackageCVE-2024-42512MediumOPCFoundation.NetStandard.Opc.Ua.Core: Security Update for the OPC UA .NET Standard StackCVE-2024-42513MediumOPCFoundation.NetStandard.Opc.Ua.Bindings.Https: Security Update for the OPC UA .NET Standard StackCVE-2024-57716MediumAutoQueryable: AutoQueryable leaks sensitive informationCVE-2025-26620MediumDuende.AccessTokenManagement: Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credentials Access TokensCVE-2025-24895CriticalCIE.AspNetCore.Authentication: AspNetCore Remote Authenticator for CIE3.0 Allows SAML Response Signature Verification BypassCVE-2025-24894CriticalSPID.AspNetCore.Authentication: The AspNetCore Remote Authenticator for SPID Allows SAML Response Signature Verification BypassGHSA-F8MX-CWFH-7HR2Mediumtshock: TShock allows chat while not fully connected, possible ban evasionCVE-2025-24788MediumSnowflake.Data: Snowflake.Data has weak temporary files permissionsCVE-2024-51417HighSystem.Linq.Dynamic.Core: Property reflection in System.Linq.Dynamic.CoreCVE-2024-10761MediumUmbraco.Cms: XSS/HTML Injection Vulnerability in Umbraco Preview BadgeCVE-2025-24011MediumUmbraco.Cms: Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes CVE-2025-24012MediumUmbraco.Cms.StaticAssets: XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Stop the waste.
Protect your environment with Kodem.