Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-48109
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
CVE-2026-46520
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVE-2026-47165
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
CVE-2026-46693
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
CVE-2026-45624
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVE-2026-46521
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVE-2026-45664
ImageMagick: Policy Bypass in MNG coder could
CVE-2026-46523
ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-46559
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
CVE-2026-46522
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-42326
ImageMagick: Heap Buffer Over-Read in IPTC encoder
CVE-2026-45358
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
CVE-2026-45031
ImageMagick: Policy Bypass in PSD decoder
CVE-2026-45359
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-42899
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2018-1002206
Directory Traversal in SharpCompress
CVE-2026-45288
Marten has an injection vulnerability in its full-text search regConfig parameter
CVE-2022-24512
.NET Remote Code Execution Vulnerability
CVE-2022-24464
.NET Denial of Service Vulnerability
CVE-2022-29145
.NET Denial of Service Vulnerability
CVE-2022-38013
.NET Denial of Service Vulnerability
CVE-2026-44213
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
GHSA-92vj-hp7m-gwcj
Nerdbank.MessagePack has Inefficient CPU Computation
GHSA-qjvr-435c-5fjh
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
CVE-2026-32933
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
CVE-2026-47166
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
CVE-2026-46692
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-vf33-6r7x-66xx
ImageMagick: Division by Zero in binomial kernel
GHSA-qv2q-c278-pch5
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
GHSA-jqq5-8px3-9m6m
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
CVE-2026-45785
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
GHSA-24c8-4792-22hx
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
CVE-2015-5237
protobuf susceptible to buffer overflow
CVE-2026-35433
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
CVE-2026-32175
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
GHSA-5r97-79vw-qvm4
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
GHSA-c55g-rp4x-fx84
Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds
CVE-2026-44375
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-44302
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-42348
OpAMP client reads unbounded HTTP response bodies
CVE-2026-43937
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
CVE-2026-43939
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
CVE-2026-43938
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
CVE-2026-41511
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
CVE-2026-32178
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
CVE-2026-42241
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVE-2025-55004
imagemagick: heap-buffer overflow read in MNG magnification with alpha
CVE-2026-40169
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
CVE-2025-62594
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
CVE-2026-40183
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
CVE-2025-66628
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
CVE-2025-68469
ImageMagick has a heap-buffer-overflow
CVE-2026-40312
ImageMagick has an off-by-one error in MSL decoder could result in crash
CVE-2025-53015
ImageMagick has XMP profile write that triggers hang due to unbounded loop
Ready to move
Start Securing
Free, no credit card | First findings in minutes