Nuget
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Nuget, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Nuget CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High2
- Medium4
Latest CVEs
The 7 most recently published vulnerabilities affecting Nuget.
- CVE-2023-29337NuGet Client Remote Code Execution Vulnerability7.1
- CVE-2022-41064.NET Framework Information Disclosure Vulnerability5.8
- CVE-2022-30184.NET and Visual Studio Information Disclosure Vulnerability5.5
- CVE-2021-21658Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.9.1
- CVE-2019-1258Azure Active Directory Authentication Library Elevation of Privilege Vulnerability8.8
- CVE-2019-0976A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), ak...5.5
- CVE-2019-0757A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager T...6.5
Product grouping is registry-driven, with AI assist and human review. How it works