Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.5
NuGet

CVE-2026-45591

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

MEDIUM 6.2
NuGet

CVE-2026-46557

ImageMagick: Stack overflow in fx operation

HIGH 8.2
NuGet

CVE-2026-48109

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

HIGH 7.5
NuGet

CVE-2026-46520

ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions

MEDIUM 4.1
NuGet

CVE-2026-47165

ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model

MEDIUM 4.1
NuGet

CVE-2026-46693

ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

MEDIUM 5.1
NuGet

CVE-2026-45624

ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.

MEDIUM 5.5
NuGet

CVE-2026-46521

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

MEDIUM 5.3
NuGet

CVE-2026-45664

ImageMagick: Policy Bypass in MNG coder could

MEDIUM 6.2
NuGet

CVE-2026-46523

ImageMagick: Use-After-Free in MSL decoder.

MEDIUM 4.0
NuGet

CVE-2026-46559

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

HIGH 7.5
NuGet

CVE-2026-46522

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

MEDIUM 5.1
NuGet

CVE-2026-42326

ImageMagick: Heap Buffer Over-Read in IPTC encoder

MEDIUM 5.3
NuGet

CVE-2026-45358

ImageMagick: Out-of-Bounds Read of a single byte in meta encoder

MEDIUM 5.3
NuGet

CVE-2026-45031

ImageMagick: Policy Bypass in PSD decoder

MEDIUM 5.7
NuGet

CVE-2026-45359

ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define

MEDIUM 5.4
NuGet

CVE-2026-46616

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

MEDIUM 4.6
NuGet

CVE-2026-46609

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

HIGH 7.5
NuGet

CVE-2026-42899

Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability

MEDIUM 5.3
NuGet

CVE-2026-40182

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

MEDIUM 5.5
NuGet

CVE-2018-1002206

Directory Traversal in SharpCompress

CRITICAL 9.8
NuGet

CVE-2026-45288

Marten has an injection vulnerability in its full-text search regConfig parameter

MEDIUM 6.3
NuGet

CVE-2022-24512

.NET Remote Code Execution Vulnerability

HIGH 7.5
NuGet

CVE-2022-24464

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2022-29145

.NET Denial of Service Vulnerability

HIGH 7.5
NuGet

CVE-2022-38013

.NET Denial of Service Vulnerability

MEDIUM 6.5
NuGet

CVE-2026-44213

OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured

MEDIUM 5.3
NuGet

GHSA-92vj-hp7m-gwcj

Nerdbank.MessagePack has Inefficient CPU Computation

MEDIUM 5.3
NuGet

GHSA-qjvr-435c-5fjh

Nerdbank.MessagePack has a memory amplification DoS in collection deserialization

HIGH 7.5
NuGet

CVE-2026-32933

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

MEDIUM 5.7
NuGet

CVE-2026-47166

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server

MEDIUM 4.1
NuGet

CVE-2026-46692

ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

LOW 3.3
NuGet

GHSA-vf33-6r7x-66xx

ImageMagick: Division by Zero in binomial kernel

LOW 3.7
NuGet

GHSA-qv2q-c278-pch5

ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse

MEDIUM 6.2
NuGet

GHSA-jqq5-8px3-9m6m

ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix

MEDIUM 6.2
NuGet

CVE-2026-45785

OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle

UNKNOWN
NuGet

GHSA-24c8-4792-22hx

Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString

HIGH 8.8
NuGet

CVE-2015-5237

protobuf susceptible to buffer overflow

HIGH 7.3
NuGet

CVE-2026-35433

Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability

HIGH 7.5
NuGet

CVE-2026-32175

Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability

UNKNOWN
NuGet

GHSA-5r97-79vw-qvm4

Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds

UNKNOWN
NuGet

GHSA-c55g-rp4x-fx84

Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds

HIGH 7.5
NuGet

CVE-2026-44375

Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException

MEDIUM 6.5
NuGet

CVE-2026-42191

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

HIGH 7.5
NuGet

CVE-2026-44302

Snappier has an infinite loop during SnappyStream decompression with malformed framed input

MEDIUM 5.9
NuGet

CVE-2026-42348

OpAMP client reads unbounded HTTP response bodies

HIGH 8.8
NuGet

CVE-2026-43937

YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`

HIGH 7.3
NuGet

CVE-2026-43939

YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers

HIGH 8.1
NuGet

CVE-2026-43938

YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header

MEDIUM 6.2
NuGet

CVE-2026-41511

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

NONE 0.0
NuGet

CVE-2026-32178

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

MEDIUM 5.3
NuGet

CVE-2026-42241

ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width

HIGH 7.6
NuGet

CVE-2025-55004

imagemagick: heap-buffer overflow read in MNG magnification with alpha

MEDIUM 6.2
NuGet

CVE-2026-40169

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

MEDIUM 4.7
NuGet

CVE-2025-62594

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

MEDIUM 5.5
NuGet

CVE-2026-40183

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

HIGH 7.5
NuGet

CVE-2025-66628

ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)

LOW 3.3
NuGet

CVE-2025-68469

ImageMagick has a heap-buffer-overflow

MEDIUM 6.2
NuGet

CVE-2026-40312

ImageMagick has an off-by-one error in MSL decoder could result in crash

HIGH 7.5
NuGet

CVE-2025-53015

ImageMagick has XMP profile write that triggers hang due to unbounded loop

Ready to move

Start Securing

Free, no credit card | First findings in minutes