NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-24936HighMicrosoft.NetCore.App.Runtime.linux-arm: .NET Elevation of Privilege VulnerabilityCVE-2023-24895HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: .NET Remote Code Execution VulnerabilityCVE-2023-24897HighMicrosoft.NetCore.App.Runtime.win-arm: .NET Remote Code Execution VulnerabilityCVE-2023-29337HighMicrosoft.Build.NuGetSdkResolver: NuGet Client Remote Code Execution VulnerabilityCVE-2018-17107HighTGServiceInterface: tgstation-server cached user logins in legacy serverCVE-2023-34230HighSnowflake.Data: Snowflake Connector .Net Command InjectionCVE-2023-2862MediumSSCMS: SSCMS vulnerable to Cross Site ScriptingCVE-2023-27321HighOPCFoundation.NetStandard.Opc.Ua.Server: Uncontrolled Resource Consumption in OPC UA .NET Standard Reference ServerCVE-2023-31048MediumOPCFoundation.NetStandard.Opc.Ua.Core: Exposure of Sensitive Information in OPC UA .NET Standard Reference ServerCVE-2023-31287HighSerenity.Net.Core: Insufficient token expiration in SerenityCVE-2023-31286MediumSerenity.Net.Core: User account enumeration in SerenityCVE-2023-31285MediumSerenity.Net.Core: Cross Site Scripting (XSS) in SerenityCVE-2023-30626HighJellyfin.Controller: Directory traversal + file write causing arbitrary code executionCVE-2023-28260HighMicrosoft.NetCore.App.Runtime.win-arm: .NET Remote Code Execution vulnerabilityCVE-2023-28638HighSnappier: Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory bufferCVE-2022-23535CriticalLiteDB: LiteDB may deserialize bad JSON on object type using _typeCVE-2022-48282HighMongoDB.Driver: MongoDB .NET/C# Driver vulnerable to Deserialization of Untrusted DataCVE-2023-21808HighMicrosoft.NetCore.App.Runtime.win-arm: .NET Remote Code Execution Vulnerability GHSA-3W9W-9833-GCPVMediumdirectxtex_desktop_2019: Security bug in ConvertToSinglePlane when used with untrusted content from the DDS loaderCVE-2023-21893HighOracle.ManagedDataAccess: Component takeover in Oracle Data Provider for .NETCVE-2023-21538HighMicrosoft.NetCore.App.Runtime.linux-arm: .NET Denial of Service VulnerabilityCVE-2020-36620LowEnumStringValues: EnumStringValues vulnerable to Uncontrolled Resource ConsumptionCVE-2021-4248CriticalDNS: DNS NuGet package uses insufficiently random valuesCVE-2022-41089HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: .NET Remote Code Execution VulnerabilityCVE-2022-23494Mediumtinymce: Cross-site scripting vulnerability in TinyMCE alerts

Stop the waste.
Protect your environment with Kodem.