Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-56364
ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML
CVE-2021-39208
Partial path traversal in sharpcompress
CVE-2023-1289
ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS
CVE-2018-1002208
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
CVE-2023-36566
Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2022-30187
Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
GHSA-xw6w-9jjh-p9cr
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
GHSA-5rpf-x9jg-8j5p
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)
GHSA-m2p3-hwv5-xpqw
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
CVE-2026-50201
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-48796
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
CVE-2026-53464
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
CVE-2026-53465
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
CVE-2026-53463
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
CVE-2026-53462
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
CVE-2026-49219
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-48734
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
CVE-2026-48724
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
CVE-2026-48733
ImageMagick has an Infinite Loop in subimage-search with crafted image
CVE-2026-48994
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
CVE-2026-46523
ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-54779
CoreWCF: SAML token replay protection is inoperative
CVE-2026-54777
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVE-2026-54776
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVE-2026-54773
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-54778
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-54775
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVE-2026-55254
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVE-2026-45491
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-47165
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
CVE-2026-46693
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
CVE-2026-45624
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVE-2026-46521
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVE-2026-45664
ImageMagick: Policy Bypass in MNG coder could
CVE-2026-46559
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
CVE-2026-42326
ImageMagick: Heap Buffer Over-Read in IPTC encoder
CVE-2026-45358
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
CVE-2026-45031
ImageMagick: Policy Bypass in PSD decoder
CVE-2026-45359
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
CVE-2026-46616
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
CVE-2026-46609
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2018-1002206
Directory Traversal in SharpCompress
CVE-2022-24512
.NET Remote Code Execution Vulnerability
CVE-2026-44213
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
GHSA-92vj-hp7m-gwcj
Nerdbank.MessagePack has Inefficient CPU Computation
GHSA-qjvr-435c-5fjh
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
CVE-2026-47166
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
CVE-2026-46692
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-jqq5-8px3-9m6m
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
CVE-2026-45785
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-42348
OpAMP client reads unbounded HTTP response bodies
CVE-2026-41511
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
CVE-2026-42241
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVE-2026-40169
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
CVE-2025-62594
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
Ready to move
Start Securing
Free, no credit card | First findings in minutes