NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-14040Mediumbootstrap: Bootstrap vulnerable to Cross-Site Scripting (XSS)CVE-2018-0875HighMicrosoft.NETCore.Jit: .NET Core Denial of Service VulnerabilityCVE-2015-5237HighGoogle.Protobuf: protobuf susceptible to buffer overflowCVE-2022-21167HighMasuit.Tools.Core: Code Injection in Masuit.Tools.CoreCVE-2010-1459Mediummono: Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerabilityCVE-2009-4665MediumCuteEditor: CuteSoft CuteEditor Path Traversal vulnerabilityCVE-2007-0660MediumDotNetNuke.Core: DotNetNuke Vulnerable to XSS in Pass-Through ValuesCVE-2006-0743Mediumlog4net: Apache log4net format string vulnerability causes DoSCVE-2022-24849MediumDisCatSharp: Exposure of Sensitive Information to an Unauthorized Actor in DisCatSharpCVE-2022-26924HighYarp.ReverseProxy: YARP Denial of Service VulnerabilityCVE-2022-26788HighMicrosoft.PowerShell.SDK: PowerShell Elevation of Privilege VulnerabilityCVE-2022-26907MediumMicrosoft.Rest.ClientRuntime: Azure SDK for .NET Information Disclosure Vulnerability.CVE-2017-11770HighSystem.Security.Cryptography.X509Certificates: Improper Certificate ValidationCVE-2020-1469HighBond.Core.CSharp: Infinite loop in .Net BondCVE-2022-24785Highmoment: Path Traversal: 'dir/../../filename' in moment.localeCVE-2022-24789HighC1CMS.Assemblies: Server side request forgery in C1 CMSCVE-2022-0749CriticalSinGooCMS.Utility: Deserialization of Untrusted Data in SinGooCMS.UtilityCVE-2021-46703CriticalRazorEngine: Code injection in RazorEngineCVE-2022-23395Mediumjquery.cookie: Prototype Pollution in jquery.cookieCVE-2022-0609HighCefSharp.Common: Use after free in AnimationCVE-2021-32842MediumSharpZipLib: Path Traversal in SharpZipLibCVE-2021-32841MediumSharpZipLib: Path Traversal in SharpZipLibCVE-2021-32840HighSharpZipLib: Path Traversal in SharpZipLibCVE-2022-0159MediumOrchardCore: orchardcore is vulnerable to Cross-site ScriptingCVE-2024-21909HighPeterO.Cbor: Denial of service in CBOR library

Stop the waste.
Protect your environment with Kodem.