NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-HWF3-R46V-5GGXLowMagick.NET-Q16-AnyCPU: ImageMagick: Information Disclosure when printing profiles with debug enabledGHSA-QVXH-PRVR-85W2LowMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation failsGHSA-6JWG-7Q3P-5FQMLowMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free when freetype initialization failsGHSA-VGHG-5JRG-2398LowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in script operation due to missing checks GHSA-V3J6-27VC-7PW2LowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing checkGHSA-QH5G-Q395-CX4JLowMagick.NET-Q16-AnyCPU: ImageMagick: Heap-use-after-free via XMP profile could result in a crashGHSA-HC76-7MPC-QJQHMediumMagick.NET-Q16-AnyCPU: ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797GHSA-56M6-8Q75-F2RWMediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219GHSA-RVHP-75F6-9JQHLowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass possible with matrix-backed operationsCVE-2026-55628MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in concatenate operation due to missing checksCVE-2026-55597MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of argumentsCVE-2026-55595MediumMagick.NET-Q16-AnyCPU: ImageMagick: Infinite Loop in connected-components when providing invalid argumentsCVE-2026-55594MediumMagick.NET-Q16-AnyCPU: ImageMagick: Stack Overflow in MVG decoder due to missing depth check.CVE-2026-55510MediumMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free in crafted 8BIM when identifying an imageCVE-2026-53467MediumMagick.NET-Q16-AnyCPU: ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchangedCVE-2026-56170HighMicrosoft.AspNetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service VulnerabilityCVE-2026-50526HighMicrosoft.NET.Build.Containers: Microsoft Security Advisory CVE-2026-50526 – .NET Tampering VulnerabilityCVE-2026-47300HighMicrosoft.AspNetCore.Authentication.Negotiate: Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege VulnerabilityCVE-2026-47303HighMicrosoft.AspNetCore.Authentication.Negotiate: Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege VulnerabilityCVE-2026-50527HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service VulnerabilityCVE-2026-50650HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege VulnerabilityCVE-2026-50651HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service VulnerabilityCVE-2026-50659MediumMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing VulnerabilityCVE-2026-50525HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service VulnerabilityCVE-2026-50528HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

Stop the waste.
Protect your environment with Kodem.