NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-VF33-6R7X-66XXLowMagick.NET-Q16-AnyCPU: ImageMagick: Division by Zero in binomial kernelGHSA-JQQ5-8PX3-9M6MMediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fixCVE-2026-46609MediumUmbraco.Cms: Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialogCVE-2026-46616MediumUmbraco.Cms: Umbraco.Cms: Open Redirect Vulnerability in Surface ControllersCVE-2026-45785MediumOpenMcdf: OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycleGHSA-24C8-4792-22HXHighscriban: Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToStringCVE-2026-46559MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.CVE-2026-46557MediumMagick.NET-Q16-AnyCPU: ImageMagick: Stack overflow in fx operationCVE-2026-46523MediumMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free in MSL decoder.CVE-2026-46522HighMagick.NET-Q16-AnyCPU: ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustionCVE-2026-46521MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compressionCVE-2026-46520HighMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensionsCVE-2026-45664MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in MNG coder could CVE-2026-45624MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.CVE-2026-35433HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability CVE-2026-42899HighMicrosoft.AspNetCore.App.Runtime.win-arm: Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service VulnerabilityCVE-2026-32175HighMicrosoft.NetCore.App.Runtime.win-arm: Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering VulnerabilityCVE-2026-45031MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in PSD decoderCVE-2026-45358MediumMagick.NET-Q16-AnyCPU: ImageMagick: Out-of-Bounds Read of a single byte in meta encoderCVE-2026-45359MediumMagick.NET-Q16-AnyCPU: ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top defineGHSA-5R97-79VW-QVM4Mediumdirectxtk12_desktop_win10: Microsoft DirectX12: .spritefont multiply overflow only in 32-bit buildsGHSA-C55G-RP4X-FX84Mediumdirectxtk_desktop_win10: Microsoft DirectX: .spritefont multiply overflow only in 32-bit buildsCVE-2026-42326MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Read in IPTC encoderCVE-2026-45288CriticalMarten: Marten has an injection vulnerability in its full-text search regConfig parameterGHSA-88Q9-CMP2-C2VQMediumoxidize-pdf: oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)

Stop the waste.
Protect your environment with Kodem.