Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.8
NuGet

CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

HIGH 7.3
NuGet

CVE-2026-35433

Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability

HIGH 7.5
NuGet

CVE-2024-21907

Improper Handling of Exceptional Conditions in Newtonsoft.Json

HIGH 7.5
NuGet

CVE-2021-23407

Path Traversal in elFinder.Net.Core

HIGH 7.5
NuGet

CVE-2020-7791

Denial of Service in i18n

HIGH 8.7
NuGet

CVE-2021-43853

AjaxNetProfessional deserializes arbitrary JavaScript objects

HIGH 8.6
NuGet

CVE-2021-41238

Missing Authorization with Default Settings in Dashboard UI

HIGH 8.2
NuGet

CVE-2020-5261

Missing Token Replay Detection in Saml2 Authentication services for ASP.NET

HIGH 7.5
NuGet

GHSA-xcx6-vp38-8hr5

Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException

HIGH 7.5
NuGet

GHSA-wgh7-7m3c-fx25

Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)

HIGH 8.6
NuGet

GHSA-x6m9-38vm-2xhf

Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()

HIGH 7.5
NuGet

CVE-2026-49451

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

HIGH 7.5
NuGet

GHSA-c875-h985-hvrc

Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service

HIGH 7.5
NuGet

GHSA-p6q4-fgr8-vx4p

Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix

HIGH 7.5
NuGet

GHSA-v66j-x4hw-fv9g

Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service

HIGH 7.5
NuGet

GHSA-grr9-747v-xvcp

Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)

HIGH 7.5
NuGet

CVE-2026-50196

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

HIGH 7.5
NuGet

CVE-2026-50200

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

HIGH 8.2
NuGet

CVE-2026-50194

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

HIGH 7.5
NuGet

CVE-2026-53460

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

HIGH 7.5
NuGet

CVE-2026-53461

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

HIGH 7.5
NuGet

CVE-2026-49218

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

HIGH 7.5
NuGet

CVE-2026-48511

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

HIGH 7.5
NuGet

CVE-2026-48506

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

HIGH 7.5
NuGet

CVE-2026-48510

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

HIGH 8.2
NuGet

CVE-2026-48109

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

HIGH 7.5
NuGet

CVE-2026-46522

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

HIGH 7.5
NuGet

CVE-2026-32175

Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability

HIGH 7.5
NuGet

CVE-2026-45591

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

HIGH 7.4
NuGet

CVE-2026-54783

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

HIGH 7.4
NuGet

CVE-2026-54781

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

HIGH 7.4
NuGet

CVE-2026-54784

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

HIGH 7.4
NuGet

CVE-2026-54774

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

HIGH 7.5
NuGet

CVE-2026-54772

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

HIGH 7.5
NuGet

CVE-2026-46520

ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions

HIGH 7.5
NuGet

CVE-2026-42899

Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2022-24464

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2022-29145

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2022-38013

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-32933

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

HIGH 8.8
NuGet

CVE-2015-5237

protobuf susceptible to buffer overflow

HIGH 7.5
NuGet

CVE-2026-44375

Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException

HIGH 7.5
NuGet

CVE-2026-44302

Snappier has an infinite loop during SnappyStream decompression with malformed framed input

HIGH 8.8
NuGet

CVE-2026-43937

YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`

HIGH 7.3
NuGet

CVE-2026-43939

YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers

HIGH 8.1
NuGet

CVE-2026-43938

YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header

HIGH 7.6
NuGet

CVE-2025-55004

imagemagick: heap-buffer overflow read in MNG magnification with alpha

HIGH 7.5
NuGet

CVE-2025-66628

ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)

HIGH 7.5
NuGet

CVE-2025-53015

ImageMagick has XMP profile write that triggers hang due to unbounded loop

HIGH 7.5
NuGet

CVE-2026-26171

Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-33116

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

HIGH 8.0
NuGet

CVE-2026-40321

DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

HIGH 7.5
NuGet

CVE-2026-33901

ImageMagick has a heap Buffer Overflow in ImageMagick MVG decoder

HIGH 7.5
NuGet

CVE-2026-33908

ImageMagick has a Stack Overflow in DestroyXMLTree()

HIGH 7.5
NuGet

GHSA-f5v8-v6q3-q4h6

Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)

HIGH 7.1
NuGet

CVE-2026-39959

Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service

HIGH 8.2
NuGet

CVE-2026-25794

ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions

HIGH 7.8
NuGet

CVE-2026-26131

.NET Elevation of Privilege Vulnerability

HIGH 7.5
NuGet

CVE-2026-26130

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2026-26127

.NET Denial of Service Vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes