NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32179CriticalMicrosoft.Native.Quic.MsQuic.OpenSSL: MsQuic has a Remote Elevation of Privilege VulnerabilityGHSA-G4VJ-CJJJ-V7HGLowNuGet.Packaging: Defense in Depth update for NuGet ClientCVE-2026-41134Highkiota: Kiota: Code Generation Literal InjectionGHSA-FCPV-W245-R2Q7LowDotNetNuke.Core: DotNetNuke.Core security code analysis rules triggeredGHSA-X928-4434-CRQJLowMagick.NET-Q16-AnyCPU: ImageMagick has a memory leak in PNG encoder when writing a MNG imageCVE-2026-56370LowMagick.NET-Q16-AnyCPU: ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifactsGHSA-8VFJ-Q2CP-5M5JLowMagick.NET-Q16-AnyCPU: ImageMagick has a heap buffer overflow read in magnify operation via unrecognized magnify:method valueGHSA-98CP-RJ9F-6V5GMediumMagick.NET-Q16-AnyCPU: ImageMagick has has a stack-buffer-overflow in MNG encoder with oversized palleteGHSA-Q8H3-JV9V-57QXLowMagick.NET-Q16-AnyCPU: ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processingGHSA-W54J-7WPM-CRHJLowMagick.NET-Q16-AnyCPU: ImageMagick has a heap-buffer-overflow in FTXT encoderCVE-2026-26171HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability CVE-2026-33116HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability CVE-2026-32178LowMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability CVE-2026-40312MediumMagick.NET-Q16-AnyCPU: ImageMagick has an off-by-one error in MSL decoder could result in crashCVE-2026-40311MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.CVE-2026-40310MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap out-of-bounds write in JP2 encoderCVE-2026-40183MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit floatCVE-2026-40169MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.CVE-2026-33905MediumMagick.NET-Q16-AnyCPU: ImageMagick has an out-of-bounds read in sample operationCVE-2026-33902MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Stack Overflow via Recursive FX Expression ParsingCVE-2026-33901HighMagick.NET-Q16-AnyCPU: ImageMagick has a heap Buffer Overflow in ImageMagick MVG decoderCVE-2026-33908HighMagick.NET-Q16-AnyCPU: ImageMagick has a Stack Overflow in DestroyXMLTree()CVE-2026-33899MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.CVE-2026-34238MediumMagick.NET-Q16-AnyCPU: ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit buildsCVE-2026-33900MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds

Stop the waste.
Protect your environment with Kodem.