NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40306MediumDotNetNuke.Core: DNN: Same HostGUID for all new installsCVE-2026-40305MediumDotNetNuke.Core: DNN: Force Friend Request AcceptanceCVE-2026-40321HighDotNetNuke.Core: DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploadCVE-2026-40021Mediumlog4net: Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden charactersCVE-2026-39959HighTmds.DBus: Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of serviceGHSA-32WQ-PPWG-3W4MHighEnhancedLinq.Async: EnhancedLinq.Async is Vulnerable to Denial of Service via Transitive Dependency Microsoft.Bcl.MemoryGHSA-MVM6-F9R3-FGFXHighAWSSDK.CloudFront: AWS SDK for .NET: Improper escaping of special characters in CloudFront policy document constructionGHSA-9R56-3GJQ-HQF7LowMagick.NET-Q16-AnyCPU: ImageMagick: META reader memory leak in the APP1JPEG input pathGHSA-6P22-Q7W5-33PGLowMagick.NET-Q16-AnyCPU: ImageMagick has possible memory leak in ASHLAR coder when action failsCVE-2026-33536MediumMagick.NET-Q16-AnyCPU: ImageMagick has an Out-of-bounds Write via InterpretImageFilenameCVE-2026-33535MediumMagick.NET-Q16-AnyCPU: ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interactionGHSA-XW6W-9JJH-P9CRMediumScriban: Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression EvaluationGHSA-M2P3-HWV5-XPQWMediumScriban: Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToStringGHSA-XCX6-VP38-8HR5HighScriban: Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowExceptionGHSA-V66J-X4HW-FV9GHighScriban: Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of ServiceGHSA-C875-H985-HVRCHighscriban: Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of ServiceGHSA-5WR9-M6JW-XX44Criticalscriban: Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuseGHSA-X6M9-38VM-2XHFHighscriban: Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset() GHSA-P6Q4-FGR8-VX4PHighScriban: Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit FixGHSA-5RPF-X9JG-8J5PMediumscriban: Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)GHSA-GRR9-747V-XVCPHighscriban: Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)GHSA-WGH7-7M3C-FX25Highscriban: Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)CVE-2026-32636MediumMagick.NET-Q16-AnyCPU: ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crashCVE-2026-32933HighAutoMapper: AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled RecursionGHSA-8FH9-C4JQ-94H4Highidunno.AtProto: idunno.Bluesky, idunno.AtProto and idunno.AtProto.OAuthCallback Denial of Service Vulnerability

Stop the waste.
Protect your environment with Kodem.