Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-26118
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2026-35433
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
CVE-2026-56379
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-56378
ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS
CVE-2026-56365
ImageMagick has a memory leak in PNG encoder when writing a MNG image
CVE-2026-56371
ImageMagick: Memory leak in coders/txt.c without freetype
CVE-2026-56376
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
CVE-2026-56369
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
CVE-2026-56363
ImageMagick: Division by Zero in binomial kernel
CVE-2026-25984
ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds
CVE-2026-56361
ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing
CVE-2026-56364
ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML
CVE-2024-21907
Improper Handling of Exceptional Conditions in Newtonsoft.Json
CVE-2024-21909
Denial of service in CBOR library
CVE-2021-23407
Path Traversal in elFinder.Net.Core
CVE-2021-23758
Remote Code Execution in AjaxNetProfessional
CVE-2020-7791
Denial of Service in i18n
CVE-2021-39208
Partial path traversal in sharpcompress
CVE-2021-43853
AjaxNetProfessional deserializes arbitrary JavaScript objects
CVE-2023-1289
ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS
CVE-2021-41238
Missing Authorization with Default Settings in Dashboard UI
CVE-2020-5261
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
CVE-2018-1002208
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
CVE-2023-36566
Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2022-30187
Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
GHSA-7jvp-hj45-2f2m
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
GHSA-6q7j-xr26-3h2c
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
GHSA-xw6w-9jjh-p9cr
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
GHSA-xcx6-vp38-8hr5
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
GHSA-wgh7-7m3c-fx25
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
GHSA-x6m9-38vm-2xhf
Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()
CVE-2026-49451
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
GHSA-5rpf-x9jg-8j5p
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)
GHSA-c875-h985-hvrc
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
GHSA-q6rr-fm2g-g5x8
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
GHSA-p6q4-fgr8-vx4p
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
GHSA-v66j-x4hw-fv9g
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
GHSA-grr9-747v-xvcp
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
GHSA-5wr9-m6jw-xx44
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse
GHSA-m2p3-hwv5-xpqw
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
CVE-2026-50268
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVE-2026-50201
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50196
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50202
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50200
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50194
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-48796
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
GHSA-24c8-4792-22hx
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
CVE-2026-53464
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
CVE-2026-53465
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
CVE-2026-53463
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
CVE-2026-53462
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
CVE-2026-53460
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
CVE-2026-49219
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-48734
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
CVE-2026-53461
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
CVE-2026-48724
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
CVE-2026-48733
ImageMagick has an Infinite Loop in subimage-search with crafted image
CVE-2026-48994
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
Ready to move
Start Securing
Free, no credit card | First findings in minutes