VulnSea

Tagged “nuget”

CVEs tagged nuget, newest first.

151 CVEsRSS

CVE-2026-81868Medium· 6.5
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCe…

SunlitSteeltoeOSS · security-advisoriesEPSS 0.16%via NVD
CVE-2026-81515High· 7.5
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognize…

TwilightSteeltoeOSS · security-advisoriesEPSS 0.34%via NVD
CVE-2026-75523Medium· 5.9
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…

SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.29%via NVD
CVE-2026-75513Critical· 9.1PoC
5d ago

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQ…

AbyssalJasperFx · martenEPSS 0.35%via NVD
CVE-2026-85756High· 7.5
5d ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot…

Twilightsshnet · SSH.NETEPSS 0.57%via NVD
CVE-2026-54632High· 7.5
1w ago

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted b…

Twilightsipsorcery-org · sipsorceryEPSS 0.54%via NVD
GHSA-mqvm-gmc4-6rv2High· 8.8
1w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
GHSA-4qhr-qf46-fcrxHigh· 8.8
1w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
GHSA-v3f6-m9j2-437pMedium· 5.9
1w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

SunlitMicrosoft · Microsoft.AspNetCore.Server.IISIntegrationvia GHSA
CVE-2026-81192High· 7.0
1w ago

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute dete…

Twilightopen-telemetry · opentelemetry-dotnet-contribEPSS 0.14%via NVD
GHSA-q72m-f2r4-w4cwHigh· 8.8
1w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
CVE-2026-71328High· 8.8
1w ago

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · visual_studio_2022EPSS 0.57%via NVD
CVE-2026-69522High· 8.8
1w ago

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.80%via NVD
CVE-2026-69439High· 8.8
1w ago

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.74%via NVD
CVE-2026-69304Medium· 5.9
1w ago

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.77%via NVD
GHSA-cvhv-g4rq-3hmwLow· 3.3
2w ago

ImageMagick: Memory Leak when providing invalid options to the cli

ImageMagick: Memory Leak when providing invalid options to the cli

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-48798High· 7.1
1mo ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the r…

TwilightSSH · SSH.NETEPSS 0.38%via NVD
CVE-2026-54570Medium· 6.9
1mo ago

AngleSharp is a .NET library for parsing angle bracket based hyper-texts

AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs is not treated as an HTML integration point when its encodin…

SunlitAngleSharp · AngleSharpEPSS 0.31%via NVD
CVE-2026-48796Medium· 5.3
1mo ago

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsW…

SunlitCefSharp · CefSharp.CommonEPSS 0.29%via NVD
GHSA-jwjp-4649-v8jpHigh· 7.5
1mo ago

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

TwilightSIPSorcery · SIPSorceryvia GHSA
GHSA-pfvm-w89x-94jwHigh· 7.5
1mo ago

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

TwilightSIPSorcery · SIPSorceryvia GHSA
GHSA-2q33-cf8w-7q23Critical· 9.8
1mo ago

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

MidnightMicrosoft · Microsoft.Native.Quic.MsQuic.OpenSSLvia GHSA
CVE-2026-62815Critical· 9.8
1mo ago

Microsoft QUIC Remote Code Execution Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Windows 11 version 23H2EPSS 1.2%via CVEORG
CVE-2026-62900Medium· 5.9
1mo ago

.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 8.0EPSS 0.78%via CVEORG
CVE-2026-62901High· 7.5
1mo ago

.NET Denial of Service Vulnerability

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-62886High· 7.8
1mo ago

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Twilightmicrosoft · visual_studio_2022EPSS 0.40%via NVD
CVE-2026-62909High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-70354High· 7.8
1mo ago

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-62897High· 7.0
1mo ago

.NET Framework Remote Code Execution Vulnerability

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.34%via CVEORG
CVEs tagged “nuget” · VulnSea