nuget

842 tracked vulnerabilities.

CVE-2024-10761 MEDIUM
Umbraco CMS <= 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1 - Cross-Site Scripting via Dashboard Preview Frame Culture Parameter
Nov 04, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-43383 HIGH
Apache Lucene.Net.Replicator 4.8.0-beta00005-4.8.0-beta00016 - Remote Code Execution via JSON Deserialization
Oct 31, 2024
CVSS 8.0
EPSS 0.05
CVE-2024-50353 MEDIUM
ICG.AspNetCore.Utilities.CloudStorage < 8.0.0 - Improper Access Control in SAS Uri Duration Handling
Oct 30, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-49755 LOW
Duende IdentityServer - Info Disclosure
Oct 28, 2024
CVSS 3.1
EPSS 0.00
CVE-2024-49771 MEDIUM
MPXJ 8.3.5-13.5.0 - Path Traversal
Oct 28, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-45526 MEDIUM
OPC Foundation UA-.NETStandard <1.5.374.78 - DoS
Oct 22, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-48929 MEDIUM
Umbraco <13.5.2-10.8.7 - Info Disclosure
Oct 22, 2024
CVSS 4.2
EPSS 0.01
CVE-2024-48927 MEDIUM
Umbraco CMS 8.0-8.18.14, 10.0.0-10.8.6, 13.0-13.5.1 - Remote Code Execution via SVG Preview
Oct 22, 2024
CVSS 4.6
EPSS 0.02
CVE-2024-48926 MEDIUM
Umbraco CMS 8.0-8.18.14, 10.0-10.8.6, 13.0.0-13.5.1 - Insufficient Session Expiration
Oct 22, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-48925 NONE
Umbraco CMS 14.0.0-14.2.9 - Improper Access Control in Webhook API
Oct 22, 2024
EPSS 0.00
CVE-2024-47819 MEDIUM
Umbraco CMS 14.0.0-14.3.0 - Cross-Site Scripting in Dictionary Section
Oct 22, 2024
CVSS 4.2
EPSS 0.01
CVE-2024-48924 HIGH
MessagePack < 2.5.187 and 2.6.95-alpha-3.0.214-rc.1 - Denial of Service via Hash Collision
Oct 17, 2024
EPSS 0.00
CVE-2024-43485 HIGH
.NET 6.0.0-6.0.34 and Visual Studio 2022 17.6.0-17.6.19 - Denial of Service
Oct 08, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-43484 HIGH
.NET Framework - Denial of Service via Inefficient Algorithmic Complexity
Oct 08, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-43483 HIGH
.NET Framework - Denial of Service via Inefficient Algorithmic Complexity
Oct 08, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-38229 HIGH
Microsoft .NET and Visual Studio - Use-After-Free Remote Code Execution
Oct 08, 2024
CVSS 8.1
EPSS 0.01
CVE-2024-45302 MEDIUM
RestSharp 107.0.0-111.2.0 - CRLF Injection via AddHeader and AddDefaultHeader Methods
Aug 29, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-44930 MEDIUM
serilog-enrichers-clientinfo < 2.1.0 - Client IP Spoofing via X-Forwarded-For or Client-Ip Headers
Aug 29, 2024
CVSS 6.5
EPSS 0.01
CVE-2024-43377 MEDIUM
Umbraco CMS 14.0.0-14.1.1 - Authenticated Improper Access Control
Aug 20, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-43376 MEDIUM
Umbraco CMS 14.0.0-14.1.1 - Sensitive Information Exposure via Management API Error Messages
Aug 20, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-38168 HIGH
.NET 8.0.0-8.0.7 and Visual Studio 2022 17.6.0-17.6.17 - Denial of Service
Aug 13, 2024
CVSS 7.5
EPSS 0.03
CVE-2024-38167 MEDIUM
.NET 8.0.0-8.0.7 and Visual Studio 2022 17.6.0-17.6.17 - Cleartext Transmission of Sensitive Information
Aug 13, 2024
CVSS 6.5
EPSS 0.02
CVE-2024-39694 MEDIUM
Duende IdentityServer 6.0.0-6.0.4, 6.1.0-6.1.7, 6.2.0-6.2.4, 6.3.0-6.3.9, 7.0.0-7.0.5 Open Redirect
Jul 31, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-41799 HIGH
tgstation-server 4.0.0-6.7.9 - Path Traversal and Remote Code Execution via .dme File Path Manipulation
Jul 29, 2024
CVSS 8.4
EPSS 0.07
CVE-2024-28698 CRITICAL
CSLA .NET < 5.5.4 - Remote Code Execution via MobileFormatter Path Traversal
Jul 22, 2024
CVSS 9.8
EPSS 0.09