Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
NuGet

CVE-2026-45288

Marten has an injection vulnerability in its full-text search regConfig parameter

CRITICAL 9.8
NuGet

CVE-2026-32179

MsQuic has a Remote Elevation of Privilege Vulnerability

CRITICAL 9.1
NuGet

CVE-2026-40324

ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents

CRITICAL 9.1
NuGet

CVE-2026-40372

Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege

CRITICAL 9.1
NuGet

GHSA-5wr9-m6jw-xx44

Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse

CRITICAL 9.8
NuGet

CVE-2021-23427

Imporoper path validation in elFinder.NetCore

CRITICAL 9.8
NuGet

CVE-2024-43498

.NET Remote Code Execution Vulnerability

CRITICAL 9.1
NuGet

CVE-2024-0057

NuGet Client Security Feature Bypass Vulnerability

CRITICAL 9.9
NuGet

CVE-2025-55315

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

CRITICAL 9.8
NuGet

CVE-2021-23758

Duplicate Advisory: Remote Code Execution in AjaxNetProfessional

CRITICAL 9.9
NuGet

CVE-2025-68924

UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation

CRITICAL 10.0
NuGet

CVE-2025-67288

Umbraco CMS has an arbitrary file upload vulnerability

CRITICAL 9.1
NuGet

CVE-2026-24838

DotNetNuke.Core Vulnerable to Stored XSS via Module Title

CRITICAL 9.8
NuGet

CVE-2025-54539

Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability

CRITICAL 10.0
NuGet

CVE-2025-64095

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CRITICAL 9.0
NuGet

CVE-2025-59545

DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

CRITICAL 9.2
NuGet

CVE-2025-43858

YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

CRITICAL 9.8
NuGet

CVE-2025-29953

Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability

CRITICAL 9.8
NuGet

CVE-2019-12277

Blogifier does not properly restrict APIs

CRITICAL 9.8
NuGet

CVE-2021-46703

Code injection in RazorEngine

CRITICAL 9.1
NuGet

CVE-2025-24895

AspNetCore Remote Authenticator for CIE3.0 Allows SAML Response Signature Verification Bypass

CRITICAL 9.1
NuGet

CVE-2025-24894

The AspNetCore Remote Authenticator for SPID Allows SAML Response Signature Verification Bypass

CRITICAL 9.8
NuGet

CVE-2021-26701

.NET Core Remote Code Execution Vulnerability

CRITICAL 9.8
NuGet

GHSA-7r36-jf3c-jhp4

Duplicate Advisory: tgstation-server vulnerable to cached user logins in legacy server

CRITICAL 9.8
NuGet

CVE-2015-2794

The installation wizard in DotNetNuke (DNN) allows privilege escalation

CRITICAL 9.8
NuGet

CVE-2021-24112

.NET Core Remote Code Execution Vulnerability

CRITICAL 9.8
NuGet

CVE-2024-48510

DotNetZip Directory Traversal vulnerability

CRITICAL 9.8
NuGet

GHSA-8rxm-6783-qh55

Duplicate Advisory: .NET and Visual Studio Remote Code Execution Vulnerability

CRITICAL 9.8
NuGet

CVE-2024-51501

CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

CRITICAL 9.8
NuGet

CVE-2024-28698

CLSA Directory Traversal vulnerability

CRITICAL 9.1
NuGet

GHSA-jw42-5m4v-9c8g

Duplicate Advisory: NuGet Client Security Feature Bypass Vulnerability

CRITICAL 9.8
NuGet

CVE-2014-4172

Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability

CRITICAL 9.8
NuGet

CVE-2018-1285

XML External Entity attack in log4net

CRITICAL 9.8
NuGet

CVE-2018-1000120

curl FTP path confusion leads to NIL byte out of bounds write

CRITICAL 9.8
NuGet

CVE-2023-32571

Dynamic Linq vulnerable to remote code execution

CRITICAL 9.8
NuGet

CVE-2019-15151

Double Free in Adplug

CRITICAL 9.8
NuGet

CVE-2019-9845

MadsKristensen.AspNetCore.Miniblog subject to Improper Input Validation

CRITICAL 9.1
NuGet

CVE-2021-29508

Insecure deserialization in Wire

CRITICAL 9.8
NuGet

CVE-2021-43569

Improper Verification of Cryptographic Signature in starkbank-ecdsa

CRITICAL 9.8
NuGet

CVE-2017-0223

ChakraCore RCE Vulnerability

CRITICAL 9.8
NuGet

CVE-2020-20136

QuantConnect Lean vulnerable to insecure deserialization

CRITICAL 9.8
NuGet

CVE-2019-20627

AutoUpdater.NET allows XXE

CRITICAL 9.8
NuGet

CVE-2017-8658

ChakraCore RCE Vulnerability

CRITICAL 9.8
NuGet

CVE-2021-33318

Improper Input Validation in IpMatcher

CRITICAL 9.8
NuGet

CVE-2018-8500

ChakraCore RCE Vulnerability

CRITICAL 9.8
NuGet

CVE-2017-0252

ChakraCore RCE Vulnerability

CRITICAL 9.8
NuGet

CVE-2017-11767

ChakraCore vulnerable to privilege escalation

CRITICAL 9.0
NuGet

CVE-2022-39256

Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.

CRITICAL 9.8
NuGet

CVE-2022-35540

Use of Hard-coded Credentials in AgileConfig.Client

CRITICAL 9.8
NuGet

CVE-2022-23535

LiteDB may deserialize bad JSON on object type using _type

CRITICAL 9.8
NuGet

CVE-2022-0749

Deserialization of Untrusted Data in SinGooCMS.Utility

CRITICAL 9.8
NuGet

CVE-2021-4248

DNS NuGet package uses insufficiently random values

CRITICAL 9.8
NuGet

CVE-2021-31819

Remote Code Execution in Halibut

CRITICAL 9.8
NuGet

CVE-2020-27998

Missing Authorization in FastReport

CRITICAL 9.8
NuGet

CVE-2019-7644

Critical severity vulnerability that affects Auth0-WCF-Service-JWT

CRITICAL 9.8
NuGet

CVE-2017-9785

Deserialization of Untrusted Data in NancyFX Nancy

CRITICAL 9.8
NuGet

CVE-2017-9246

New Relic .NET Agent contains SQL Injection

Ready to move

Start Securing

Free, no credit card | First findings in minutes