Tagged “nuget”
CVEs tagged nuget, newest first.
159 CVEsRSS
CVE-2026-48733Medium· 4.7ImageMagick has an Infinite Loop in subimage-search with crafted image
ImageMagick has an Infinite Loop in subimage-search with crafted image
CVE-2026-48734Medium· 5.5ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
CVE-2026-48994Medium· 5.9ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
CVE-2026-49218High· 7.5ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-53460High· 7.5ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
CVE-2026-53461High· 7.5ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
GHSA-98gv-6gmj-cm6mLowDuplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype
Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype
GHSA-8g9f-ccmr-vfvgMedium· 3.7Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-v772-658q-978pLowDuplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-56379High· 8.1ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…
CVE-2026-56371Medium· 5.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…
GHSA-c2g3-c4gc-w5wgHighReDoS in DotVVM routing
ReDoS in DotVVM routing
GHSA-c8qj-jx8j-fg2wCriticalDotVVM: Missing authorization in AuthorizeActionFilter
DotVVM: Missing authorization in AuthorizeActionFilter
GHSA-2rm3-333w-xvc4Medium· 5.3DotVVM: Unrestricted file upload
DotVVM: Unrestricted file upload
CVE-2026-54772High· 7.5CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVE-2026-54773Medium· 5.9CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-54774High· 7.4CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVE-2026-54775Medium· 6.5CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVE-2026-54776Medium· 4.4CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVE-2026-54777Medium· 6.5CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVE-2026-54778Medium· 6.2CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-54779Medium· 5.9CoreWCF: SAML token replay protection is inoperative
CoreWCF: SAML token replay protection is inoperative
CVE-2026-54780Low· 3.7CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-54781High· 7.4CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVE-2026-54782Critical· 10.0CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVE-2026-54783High· 7.4CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-55254Medium· 4.8NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVE-2026-48109High· 8.2MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input