Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.8
NuGet

CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

HIGH 7.3
NuGet

CVE-2026-35433

Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability

NONE 0.0
NuGet

CVE-2026-56379

ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

LOW 3.7
NuGet

CVE-2026-56378

ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS

LOW 3.7
NuGet

CVE-2026-56365

ImageMagick has a memory leak in PNG encoder when writing a MNG image

NONE 0.0
NuGet

CVE-2026-56371

ImageMagick: Memory leak in coders/txt.c without freetype

LOW 3.7
NuGet

CVE-2026-56376

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

LOW 3.7
NuGet

CVE-2026-56369

ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse

LOW 3.3
NuGet

CVE-2026-56363

ImageMagick: Division by Zero in binomial kernel

LOW 3.7
NuGet

CVE-2026-25984

ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds

LOW 3.3
NuGet

CVE-2026-56361

ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing

MEDIUM 6.5
NuGet

CVE-2026-56364

ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML

HIGH 7.5
NuGet

CVE-2024-21907

Improper Handling of Exceptional Conditions in Newtonsoft.Json

UNKNOWN
NuGet

CVE-2024-21909

Denial of service in CBOR library

HIGH 7.5
NuGet

CVE-2021-23407

Path Traversal in elFinder.Net.Core

CRITICAL 9.8
NuGet

CVE-2021-23758

Remote Code Execution in AjaxNetProfessional

HIGH 7.5
NuGet

CVE-2020-7791

Denial of Service in i18n

MEDIUM 4.3
NuGet

CVE-2021-39208

Partial path traversal in sharpcompress

HIGH 8.7
NuGet

CVE-2021-43853

AjaxNetProfessional deserializes arbitrary JavaScript objects

MEDIUM 5.5
NuGet

CVE-2023-1289

ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS

HIGH 8.6
NuGet

CVE-2021-41238

Missing Authorization with Default Settings in Dashboard UI

HIGH 8.2
NuGet

CVE-2020-5261

Missing Token Replay Detection in Saml2 Authentication services for ASP.NET

MEDIUM 5.5
NuGet

CVE-2018-1002208

Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib

MEDIUM 6.5
NuGet

CVE-2023-36566

Microsoft Common Data Model SDK Denial of Service Vulnerability

MEDIUM 4.7
NuGet

CVE-2022-30187

Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library

UNKNOWN
NuGet

GHSA-7jvp-hj45-2f2m

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

UNKNOWN
NuGet

GHSA-6q7j-xr26-3h2c

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

MEDIUM 6.5
NuGet

GHSA-xw6w-9jjh-p9cr

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

HIGH 7.5
NuGet

GHSA-xcx6-vp38-8hr5

Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException

HIGH 7.5
NuGet

GHSA-wgh7-7m3c-fx25

Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)

HIGH 8.6
NuGet

GHSA-x6m9-38vm-2xhf

Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()

HIGH 7.5
NuGet

CVE-2026-49451

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

MEDIUM 5.3
NuGet

GHSA-5rpf-x9jg-8j5p

Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)

HIGH 7.5
NuGet

GHSA-c875-h985-hvrc

Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service

UNKNOWN
NuGet

GHSA-q6rr-fm2g-g5x8

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

HIGH 7.5
NuGet

GHSA-p6q4-fgr8-vx4p

Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix

HIGH 7.5
NuGet

GHSA-v66j-x4hw-fv9g

Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service

HIGH 7.5
NuGet

GHSA-grr9-747v-xvcp

Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)

CRITICAL 9.1
NuGet

GHSA-5wr9-m6jw-xx44

Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse

MEDIUM 6.5
NuGet

GHSA-m2p3-hwv5-xpqw

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

LOW 1.9
NuGet

CVE-2026-50268

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

MEDIUM 6.5
NuGet

CVE-2026-50201

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

HIGH 7.5
NuGet

CVE-2026-50196

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

MEDIUM 5.9
NuGet

CVE-2026-50202

Steeltoe's static JWKS cache shared across schemes and never invalidated

MEDIUM 4.7
NuGet

CVE-2026-50267

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

HIGH 7.5
NuGet

CVE-2026-50200

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

HIGH 8.2
NuGet

CVE-2026-50194

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

MEDIUM 5.3
NuGet

CVE-2026-48796

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

UNKNOWN
NuGet

GHSA-24c8-4792-22hx

Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString

MEDIUM 4.0
NuGet

CVE-2026-53464

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

MEDIUM 6.2
NuGet

CVE-2026-53465

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

MEDIUM 4.3
NuGet

CVE-2026-53463

ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments

MEDIUM 5.9
NuGet

CVE-2026-53462

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

HIGH 7.5
NuGet

CVE-2026-53460

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

MEDIUM 5.5
NuGet

CVE-2026-49219

ImageMagick: Policy Bypass can read disallowed files via symlink

MEDIUM 5.5
NuGet

CVE-2026-48734

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

HIGH 7.5
NuGet

CVE-2026-53461

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

MEDIUM 5.5
NuGet

CVE-2026-48724

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

MEDIUM 4.7
NuGet

CVE-2026-48733

ImageMagick has an Infinite Loop in subimage-search with crafted image

MEDIUM 5.9
NuGet

CVE-2026-48994

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

Ready to move

Start Securing

Free, no credit card | First findings in minutes