boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

NuGet

Package ecosystem NuGet. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
34346

Monthly trend

▂▁▁█

2026-07 4 · 2026-08 0 · 2026-09 1 · 2026-10 29

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-559698.762.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-478968.955.5—Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator rep…
CVE-2026-478978.952.5—Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator …
CVE-2026-866008.241.7—Workload identity attestation generated before login host validation in Snowflake drivers
CVE-2026-478984.038.5—Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
CVE-2026-635678.238.4—IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
CVE-2026-824588.734.8—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-1036038.733.4—Unbounded HSS public key level count allows huge array allocation during signature veri…
CVE-2026-635699.131.6—MTI/A0 DHAgreement does not validate the peer's ephemeral value
CVE-2026-635668.729.0—DTLS handshake reassembler allocates buffer from unchecked 24-bit length
CVE-2026-1052395.325.1—Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-1052415.325.1—Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-1052425.325.1—Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-1052445.325.1—Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-1052405.324.2—Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-1052435.324.2—Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-635727.124.1—Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files
CVE-2026-635787.124.1—Unbounded PBE iteration count when decrypting PKCS#8 private keys
CVE-2026-635688.722.8—Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion
CVE-2026-635748.722.4—Unbounded allocation from OpenPGP signature and user attribute subpacket lengths

Most-affected packages

Packages with the most advisories
PackageCVEs
BouncyCastle.Cryptography21
log4net6
ApacheThrift3
Lucene.Net.Replicator2
Lucene.Net.Analysis.Common1
Snowflake.Data1