Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-100368
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
CVE-2026-100369
CliInvoke: Argument Injection in Extensibility Runner Factory
CVE-2026-56379
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-56371
ImageMagick: Memory leak in coders/txt.c without freetype
CVE-2026-56376
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-8g9f-ccmr-vfvg
Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-98gv-6gmj-cm6m
Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype
GHSA-v772-658q-978p
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-65829
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
CVE-2026-56370
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
CVE-2026-81516
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
CVE-2026-81868
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
CVE-2026-81515
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
CVE-2026-75523
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
CVE-2026-85756
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
CVE-2026-69197
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
CVE-2026-75513
Marten's LINQ provider has SQL injection via unescaped string literals
CVE-2026-81192
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
CVE-2026-71328
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-50524
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
CVE-2026-47302
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
CVE-2026-50651
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
CVE-2026-50659
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
CVE-2026-57108
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
CVE-2026-32178
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
CVE-2026-62363
ImageMagick: Heap Buffer Over-Write in fx operation
CVE-2026-50525
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
CVE-2026-50648
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
CVE-2026-48796
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
CVE-2026-46523
ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-26130
.NET Denial of Service Vulnerability
CVE-2026-33535
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
CVE-2026-26171
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
CVE-2026-33536
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2026-50528
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-vh8f-65qg-3m8j
Duplicate Advisory: .NET Denial of Service Vulnerability
CVE-2026-21218
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
CVE-2025-26646
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
CVE-2025-43858
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
CVE-2024-55488
Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting
CVE-2026-42899
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-50527
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
CVE-2026-47304
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-45491
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
CVE-2026-48109
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
CVE-2026-46522
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
GHSA-g4vj-cjjj-v7hg
Defense in Depth update for NuGet Client
CVE-2026-40183
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
CVE-2026-40312
ImageMagick has an off-by-one error in MSL decoder could result in crash
CVE-2026-40169
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
CVE-2026-40891
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVE-2026-28493
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
CVE-2026-40894
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVE-2026-26127
.NET Denial of Service Vulnerability
CVE-2026-30931
ImageMagick has heap-based buffer overflow in UHDR encoder
CVE-2026-33116
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
Ready to move
Start Securing
Free, no credit card | First findings in minutes