Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.4
NuGet

CVE-2026-100368

CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers

HIGH 8.4
NuGet

CVE-2026-100369

CliInvoke: Argument Injection in Extensibility Runner Factory

NONE 0.0
NuGet

CVE-2026-56379

ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

NONE 0.0
NuGet

CVE-2026-56371

ImageMagick: Memory leak in coders/txt.c without freetype

LOW 3.7
NuGet

CVE-2026-56376

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.7
NuGet

GHSA-8g9f-ccmr-vfvg

Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder

NONE 0.0
NuGet

GHSA-98gv-6gmj-cm6m

Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype

NONE 0.0
NuGet

GHSA-v772-658q-978p

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

MEDIUM 5.3
NuGet

CVE-2026-65829

MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers

LOW 3.3
NuGet

CVE-2026-56370

ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts

HIGH 7.5
NuGet

CVE-2026-81516

Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)

MEDIUM 6.5
NuGet

CVE-2026-81868

Steeltoe: Header-forwarded client cert lacks proof of private-key possession

HIGH 7.5
NuGet

CVE-2026-81515

Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)

MEDIUM 5.9
NuGet

CVE-2026-75523

Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

HIGH 7.5
NuGet

CVE-2026-85756

SSH.NET: ScpClient allows server-side RCE via default SCP path handling

UNKNOWN
NuGet

CVE-2026-69197

Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion

CRITICAL 9.1
NuGet

CVE-2026-75513

Marten's LINQ provider has SQL injection via unescaped string literals

HIGH 7.0
NuGet

CVE-2026-81192

OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

HIGH 8.8
NuGet

CVE-2026-71328

Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

HIGH 7.5
NuGet

CVE-2026-50524

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-47302

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-50651

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

MEDIUM 6.5
NuGet

CVE-2026-50659

Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability

HIGH 7.5
NuGet

CVE-2026-57108

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

NONE 0.0
NuGet

CVE-2026-32178

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

MEDIUM 5.0
NuGet

CVE-2026-62363

ImageMagick: Heap Buffer Over-Write in fx operation

HIGH 7.5
NuGet

CVE-2026-50525

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-50648

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

MEDIUM 5.3
NuGet

CVE-2026-48796

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

MEDIUM 6.2
NuGet

CVE-2026-46523

ImageMagick: Use-After-Free in MSL decoder.

HIGH 7.5
NuGet

CVE-2026-26130

.NET Denial of Service Vulnerability

MEDIUM 4.0
NuGet

CVE-2026-33535

ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction

HIGH 7.5
NuGet

CVE-2026-26171

Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability

MEDIUM 5.1
NuGet

CVE-2026-33536

ImageMagick has an Out-of-bounds Write via InterpretImageFilename

MEDIUM 5.3
NuGet

CVE-2026-40182

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

HIGH 8.2
NuGet

CVE-2026-50528

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

HIGH 7.5
NuGet

GHSA-vh8f-65qg-3m8j

Duplicate Advisory: .NET Denial of Service Vulnerability

UNKNOWN
NuGet

CVE-2026-21218

Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability

HIGH 8.0
NuGet

CVE-2025-26646

Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability

CRITICAL 9.2
NuGet

CVE-2025-43858

YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

MEDIUM 6.5
NuGet

CVE-2024-55488

Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting

HIGH 7.5
NuGet

CVE-2026-42899

Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-45591

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-50527

Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability

HIGH 8.1
NuGet

CVE-2026-47304

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

MEDIUM 6.2
NuGet

CVE-2026-46557

ImageMagick: Stack overflow in fx operation

MEDIUM 6.8
NuGet

CVE-2026-45491

Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability

HIGH 8.2
NuGet

CVE-2026-48109

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

HIGH 7.5
NuGet

CVE-2026-46522

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

UNKNOWN
NuGet

GHSA-g4vj-cjjj-v7hg

Defense in Depth update for NuGet Client

MEDIUM 5.5
NuGet

CVE-2026-40183

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

MEDIUM 6.2
NuGet

CVE-2026-40312

ImageMagick has an off-by-one error in MSL decoder could result in crash

MEDIUM 6.2
NuGet

CVE-2026-40169

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

MEDIUM 5.3
NuGet

CVE-2026-40891

OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

MEDIUM 6.5
NuGet

CVE-2026-28493

ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder

MEDIUM 5.3
NuGet

CVE-2026-40894

OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

HIGH 7.5
NuGet

CVE-2026-26127

.NET Denial of Service Vulnerability

MEDIUM 6.8
NuGet

CVE-2026-30931

ImageMagick has heap-based buffer overflow in UHDR encoder

HIGH 7.5
NuGet

CVE-2026-33116

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

MEDIUM 6.5
NuGet

CVE-2026-42191

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

Ready to move

Start Securing

Free, no credit card | First findings in minutes