Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-26118
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2026-35433
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
CVE-2024-21907
Improper Handling of Exceptional Conditions in Newtonsoft.Json
CVE-2021-23407
Path Traversal in elFinder.Net.Core
CVE-2020-7791
Denial of Service in i18n
CVE-2021-43853
AjaxNetProfessional deserializes arbitrary JavaScript objects
CVE-2021-41238
Missing Authorization with Default Settings in Dashboard UI
CVE-2020-5261
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
GHSA-xcx6-vp38-8hr5
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
GHSA-wgh7-7m3c-fx25
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
GHSA-x6m9-38vm-2xhf
Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()
CVE-2026-49451
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
GHSA-c875-h985-hvrc
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
GHSA-p6q4-fgr8-vx4p
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
GHSA-v66j-x4hw-fv9g
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
GHSA-grr9-747v-xvcp
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
CVE-2026-50196
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50194
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-53460
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
CVE-2026-53461
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
CVE-2026-49218
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
CVE-2026-48511
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
CVE-2026-48506
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
CVE-2026-48510
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVE-2026-48109
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
CVE-2026-46522
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-32175
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
CVE-2026-45591
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-54783
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CVE-2026-54781
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVE-2026-54784
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-54774
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVE-2026-54772
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVE-2026-46520
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVE-2026-42899
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
CVE-2022-24464
.NET Denial of Service Vulnerability
CVE-2022-29145
.NET Denial of Service Vulnerability
CVE-2022-38013
.NET Denial of Service Vulnerability
CVE-2026-32933
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
CVE-2015-5237
protobuf susceptible to buffer overflow
CVE-2026-44375
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVE-2026-44302
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-43937
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
CVE-2026-43939
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
CVE-2026-43938
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
CVE-2025-55004
imagemagick: heap-buffer overflow read in MNG magnification with alpha
CVE-2025-66628
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
CVE-2025-53015
ImageMagick has XMP profile write that triggers hang due to unbounded loop
CVE-2026-26171
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
CVE-2026-33116
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-40321
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
CVE-2026-33901
ImageMagick has a heap Buffer Overflow in ImageMagick MVG decoder
CVE-2026-33908
ImageMagick has a Stack Overflow in DestroyXMLTree()
GHSA-f5v8-v6q3-q4h6
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
CVE-2026-39959
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
CVE-2026-25794
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions
CVE-2026-26131
.NET Elevation of Privilege Vulnerability
CVE-2026-26130
.NET Denial of Service Vulnerability
CVE-2026-26127
.NET Denial of Service Vulnerability
Ready to move
Start Securing
Free, no credit card | First findings in minutes