VulnSea

Tagged “nuget”

CVEs tagged nuget, newest first.

159 CVEsRSS

GHSA-h58x-r7f7-rh84Low· 3.7
2mo ago

ImageMagick: Memory Leak in ICON decoder when allocation fails

ImageMagick: Memory Leak in ICON decoder when allocation fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-h5r4-w88w-7ccrLow· 2.5
2mo ago

ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified

ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-55510Medium· 5.5
2mo ago

ImageMagick: Use-After-Free in crafted 8BIM when identifying an image

ImageMagick: Use-After-Free in crafted 8BIM when identifying an image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-55594Medium· 5.3
2mo ago

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.40%via GHSA
CVE-2026-55595Medium· 4.7
2mo ago

ImageMagick: Infinite Loop in connected-components when providing invalid arguments

ImageMagick: Infinite Loop in connected-components when providing invalid arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.12%via GHSA
CVE-2026-55597Medium· 5.5
2mo ago

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-55628Medium· 6.1
2mo ago

ImageMagick: Policy Bypass in concatenate operation due to missing checks

ImageMagick: Policy Bypass in concatenate operation due to missing checks

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.14%via GHSA
GHSA-rvhp-75f6-9jqhLow· 3.3
2mo ago

ImageMagick: Policy Bypass possible with matrix-backed operations

ImageMagick: Policy Bypass possible with matrix-backed operations

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-56m6-8q75-f2rwMedium· 4.7
2mo ago

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-hc76-7mpc-qjqhMedium· 5.7
2mo ago

ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-qh5g-q395-cx4jLow· 3.7
2mo ago

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-v3j6-27vc-7pw2Low· 3.3
2mo ago

ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-vghg-5jrg-2398Low· 3.3
2mo ago

ImageMagick: Policy Bypass in script operation due to missing checks

ImageMagick: Policy Bypass in script operation due to missing checks

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-6jwg-7q3p-5fqmLow· 3.7
2mo ago

ImageMagick: Use-After-Free when freetype initialization fails

ImageMagick: Use-After-Free when freetype initialization fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-53467Medium· 5.3
2mo ago

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.33%via GHSA
CVE-2026-50273High· 7.5
2mo ago

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

▾ TwilightDatadog · Datadog.TraceEPSS 0.79%via GHSA
CVE-2026-50646High· 7.8
2mo ago

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 4.0%via CVEORG
CVE-2026-50650High· 7.8
2mo ago

.NET Framework Elevation of Privilege Vulnerability

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 0.46%via CVEORG
CVE-2026-50527High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47303High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-47300High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.78%via CVEORG
CVE-2026-50526High· 7.0
2mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.22%via CVEORG
CVE-2026-56170High· 7.5
2mo ago

ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-50524High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50648High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50528High· 8.2
2mo ago

.NET Security Feature Bypass Vulnerability

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.61%via CVEORG
CVE-2026-50525High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50659Medium· 6.5
2mo ago

.NET Spoofing Vulnerability

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.74%via CVEORG
CVE-2026-50651High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVEs tagged “nuget” — page 3 · VulnSea