NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-32028MediumOpenTelemetry.Instrumentation.Http: Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCoreCVE-2024-29992MediumAzure.Identity: Azure Identity Library for .NET Information Disclosure VulnerabilityCVE-2024-29203Mediumtinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframesCVE-2024-29881Mediumtinymce/tinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elementsCVE-2024-29187Highwix: WiX based installers are vulnerable to binary hijack when run as SYSTEMCVE-2024-29188Highwix: Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated filesGHSA-G4V6-69P6-Q3P4HighPanelSwWix4.Sdk: WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM GHSA-WQ88-FQ4X-H2PMHighPanelSW.Custom.WiX: WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEMCVE-2024-28868LowUmbracoCMS: Umbraco possible user enumeration CVE-2024-28252HighCoreWCF.NetFramingBase: CoreWCF NetFraming based services can leave connections open when they should be closedGHSA-2X7M-GF85-3745HighMicrosoft.Native.Quic.MsQuic.OpenSSL: Remote Denial of Service Vulnerability in Microsoft QUICCVE-2024-21392HighMicrosoft.NETCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2024-21392: .NET Denial of Service VulnerabilityCVE-2024-27929HighSixLabors.ImageSharp: Use After Free in SixLabors.ImageSharpCVE-2024-26470MediumFullStackHero.WebAPI.Boilerplate: FullStackHero's WebAPI Boilerplate host header injection vulnerabilityCVE-2024-26318MediumSerenity.Net.Core: Cross-site Scripting in SerenityCVE-2024-0057CriticalNuGet.CommandLine: NuGet Client Security Feature Bypass Vulnerability CVE-2024-21386HighMicrosoft.AspNetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service VulnerabilityGHSA-8V28-3G86-CHJ5HighPanelSwWix4.Sdk: PanelSwWix4.Sdk .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privilegesGHSA-259P-RVJX-FFWGHighPanelSW.Custom.WiX: Panel::Software Customized WiX .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privilegesCVE-2024-24810Highwix: WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privilegesCVE-2022-34716MediumSystem.Security.Cryptography.Xml: .NET Information Disclosure VulnerabilityGHSA-JCMQ-5RRV-J2G4HighPowerShell: PowerShell is subject to remote code execution vulnerabilityCVE-2024-23838HighTrueLayer.Client: TrueLayer.Client SSRF when fetching payment or payment providerCVE-2024-21319MediumSystem.IdentityModel.Tokens.Jwt: Microsoft ASP.NET Core project templates vulnerable to denial of serviceCVE-2024-0056HighMicrosoft.Data.SqlClient: Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass

Stop the waste.
Protect your environment with Kodem.