Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-47165
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
CVE-2026-46693
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
CVE-2026-45624
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVE-2026-46521
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVE-2026-45664
ImageMagick: Policy Bypass in MNG coder could
CVE-2026-46523
ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-46559
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
CVE-2026-42326
ImageMagick: Heap Buffer Over-Read in IPTC encoder
CVE-2026-45358
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
CVE-2026-45031
ImageMagick: Policy Bypass in PSD decoder
CVE-2026-45359
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2018-1002206
Directory Traversal in SharpCompress
CVE-2022-24512
.NET Remote Code Execution Vulnerability
CVE-2026-44213
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
GHSA-92vj-hp7m-gwcj
Nerdbank.MessagePack has Inefficient CPU Computation
GHSA-qjvr-435c-5fjh
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
CVE-2026-47166
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
CVE-2026-46692
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-jqq5-8px3-9m6m
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
CVE-2026-45785
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-42348
OpAMP client reads unbounded HTTP response bodies
CVE-2026-41511
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
CVE-2026-42241
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVE-2026-40169
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
CVE-2025-62594
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
CVE-2026-40183
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
CVE-2026-40312
ImageMagick has an off-by-one error in MSL decoder could result in crash
CVE-2026-23874
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
CVE-2026-44788
SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)
CVE-2026-41310
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
CVE-2026-41484
OneCollector exporter reads unbounded HTTP response bodies
CVE-2026-41483
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read
CVE-2026-33900
ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
CVE-2026-40305
DNN: Force Friend Request Acceptance
CVE-2026-41319
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
CVE-2026-40021
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
CVE-2026-41078
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVE-2026-34238
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
CVE-2026-40306
DNN: Same HostGUID for all new installs
CVE-2026-40891
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVE-2026-40894
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVE-2026-41173
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
CVE-2026-33899
ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.
CVE-2026-33902
ImageMagick has a Stack Overflow via Recursive FX Expression Parsing
CVE-2026-33905
ImageMagick has an out-of-bounds read in sample operation
CVE-2026-40311
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
CVE-2026-40310
ImageMagick has a heap out-of-bounds write in JP2 encoder
GHSA-98cp-rj9f-6v5g
ImageMagick has has a stack-buffer-overflow in MNG encoder with oversized pallete
CVE-2026-33536
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
CVE-2026-33535
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
GHSA-m2p3-hwv5-xpqw
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
GHSA-xw6w-9jjh-p9cr
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
CVE-2026-30935
ImageMagick has Heap Buffer Over-Read in BilateralBlurImage
CVE-2026-30931
ImageMagick has heap-based buffer overflow in UHDR encoder
CVE-2026-28493
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
Ready to move
Start Securing
Free, no credit card | First findings in minutes