NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WQCR-XM43-HPQRHighImageResizer.Plugins.FreeImage: Vulnerable version of libwebp and can be exploited with a malicious source imageGHSA-4C29-GFRP-G6X9HighCefSharp.Common: CefSharp affected by libvpx's heap buffer overflow in vp8 encodingCVE-2023-44390MediumHtmlSanitizer: HtmlSanitizer vulnerable to Cross-site Scripting in Foreign ContentGHSA-7VPR-3PPW-QRPJHighImageflow.AllPlatforms: Imageflow affected by libwebp zero-day and should not be used with malicious source images.GHSA-J646-GJ5P-P45GCriticalCefSharp.Common: CefSharp affected by heap buffer overflow in WebPCVE-2023-41890HighSustainsys.Saml2: Sustainsys.Saml2 Insufficient Identity Provider Issuer ValidationCVE-2023-36792HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2023-36792: .NET Remote Code Execution VulnerabilityCVE-2023-36794HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution VulnerabilityCVE-2023-36793HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2023-36793: .NET Remote Code Execution VulnerabilityCVE-2023-36796HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2023-36796: .NET Remote Code Execution VulnerabilityCVE-2023-36799MediumMicrosoft.NETCore.App.Runtime.linux-arm64: Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service VulnerabilityCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableCVE-2023-35391HighMicrosoft.AspNetCore.SignalR.StackExchangeRedis: .NET Information Disclosure VulnerabilityGHSA-6R78-M64M-QWCFLowmoq: Moq v4.20.0-rc to 4.20.1 share hashed user dataCVE-2023-35390HighMicrosoft.NET.Build.Containers: .NET Remote Code Execution VulnerabilityCVE-2023-38178HighMicrosoft.AspNetCore.App.Runtime.win-arm64: .NET Denial of Service VulnerabilityCVE-2023-38180HighMicrosoft.AspNetCore.App.Runtime.win-arm64: .NET Denial of Service VulnerabilityCVE-2023-37267HighUmbraco.Cms.Infrastructure: Umbraco allows possible Admin-level access to backoffice without Auth under rare conditionsCVE-2023-33127HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution VulnerabilityCVE-2023-33170HighMicrosoft.AspNetCore.Identity: Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass VulnerabilityCVE-2023-33141HighYarp.ReverseProxy: YARP Denial of Service VulnerabilityCVE-2023-32571CriticalSystem.Linq.Dynamic.Core: Dynamic Linq vulnerable to remote code executionCVE-2023-33126HighMicrosoft.NetCore.App.Runtime.win-arm: Microsoft Security Advisory CVE-2023-33126: .NET Remote Code Execution VulnerabilityCVE-2023-33128HighMicrosoft.NetCore.App.Runtime.linux-arm: .NET Remote Code Execution VulnerabilityCVE-2023-29331HighMicrosoft.Windows.Compatibility: .NET Denial of Service vulnerability

Stop the waste.
Protect your environment with Kodem.