Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Package ecosystem NuGet. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 4 | 4 | 3 |
█▁
2026-07 4 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55969 | 8.7 | 63.0 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-47896 | 8.9 | 51.2 | — | Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator rep… |
| CVE-2026-47897 | 8.9 | 46.3 | — | Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator … |
| CVE-2026-47898 | 4.0 | 28.0 | — | Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser |
| Package | CVEs |
|---|---|
| Lucene.Net.Replicator | 2 |
| ApacheThrift | 1 |
| Lucene.Net.Analysis.Common | 1 |