NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-75513CriticalMarten: Marten's LINQ provider has SQL injection via unescaped string literalsCVE-2026-81192HighOpenTelemetry.Resources.Host: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSCVE-2026-69304MediumMicrosoft.AspNetCore.Server.IISIntegration: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service VulnerabilityCVE-2026-69522HighMicrosoft.DiaSymReader.Native: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution VulnerabilityCVE-2026-69439HighMicrosoft.DiaSymReader.Native: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege VulnerabilityCVE-2026-71328HighMicrosoft.DiaSymReader.Native: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution VulnerabilityCVE-2026-50646HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution VulnerabilityCVE-2026-62815CriticalMicrosoft.Native.Quic.MsQuic.OpenSSL: Microsoft QUIC: Remote Code Execution VulnerabilityCVE-2026-62900MediumMicrosoft.Build.Tasks.Git: Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure VulnerabilityGHSA-CVHV-G4RQ-3HMWLowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak when providing invalid options to the cliGHSA-PFVM-W89X-94JWHighSIPSorcery: SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)GHSA-JWJP-4649-V8JPHighSIPSorcery: SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsingCVE-2026-48798HighSSH.NET: SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesCVE-2026-62902MediumMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure VulnerabilityCVE-2026-62871HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege VulnerabilityCVE-2026-62897HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution VulnerabilityCVE-2026-70354HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution VulnerabilityCVE-2026-62909MediumMicrosoft.NETCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege VulnerabilityCVE-2026-62886HighMicrosoft.WindowsDesktop.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege VulnerabilityCVE-2026-62901HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service VulnerabilityCVE-2026-62899MediumMicrosoft.NETCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass VulnerabilityCVE-2026-62898HighMicrosoft.NETCore.App.Runtime.win-arm64: Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure VulnerabilityCVE-2026-53466MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflowCVE-2026-32203HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service VulnerabilityCVE-2026-54632HighSIPSorcery: SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)

Stop the waste.
Protect your environment with Kodem.