Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.5
NuGet

CVE-2026-56364

ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML

MEDIUM 4.3
NuGet

CVE-2021-39208

Partial path traversal in sharpcompress

MEDIUM 5.5
NuGet

CVE-2023-1289

ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS

MEDIUM 5.5
NuGet

CVE-2018-1002208

Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib

MEDIUM 6.5
NuGet

CVE-2023-36566

Microsoft Common Data Model SDK Denial of Service Vulnerability

MEDIUM 4.7
NuGet

CVE-2022-30187

Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library

MEDIUM 6.5
NuGet

GHSA-xw6w-9jjh-p9cr

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

MEDIUM 5.3
NuGet

GHSA-5rpf-x9jg-8j5p

Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)

MEDIUM 6.5
NuGet

GHSA-m2p3-hwv5-xpqw

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

MEDIUM 6.5
NuGet

CVE-2026-50201

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

MEDIUM 5.9
NuGet

CVE-2026-50202

Steeltoe's static JWKS cache shared across schemes and never invalidated

MEDIUM 4.7
NuGet

CVE-2026-50267

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

MEDIUM 5.3
NuGet

CVE-2026-48796

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

MEDIUM 4.0
NuGet

CVE-2026-53464

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

MEDIUM 6.2
NuGet

CVE-2026-53465

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

MEDIUM 4.3
NuGet

CVE-2026-53463

ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments

MEDIUM 5.9
NuGet

CVE-2026-53462

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

MEDIUM 5.5
NuGet

CVE-2026-49219

ImageMagick: Policy Bypass can read disallowed files via symlink

MEDIUM 5.5
NuGet

CVE-2026-48734

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

MEDIUM 5.5
NuGet

CVE-2026-48724

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

MEDIUM 4.7
NuGet

CVE-2026-48733

ImageMagick has an Infinite Loop in subimage-search with crafted image

MEDIUM 5.9
NuGet

CVE-2026-48994

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

MEDIUM 6.2
NuGet

CVE-2026-46523

ImageMagick: Use-After-Free in MSL decoder.

MEDIUM 5.9
NuGet

CVE-2026-54779

CoreWCF: SAML token replay protection is inoperative

MEDIUM 6.5
NuGet

CVE-2026-54777

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

MEDIUM 4.4
NuGet

CVE-2026-54776

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

MEDIUM 5.9
NuGet

CVE-2026-54773

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

MEDIUM 6.2
NuGet

CVE-2026-54778

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

MEDIUM 6.5
NuGet

CVE-2026-54775

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

MEDIUM 4.8
NuGet

CVE-2026-55254

NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation

MEDIUM 6.8
NuGet

CVE-2026-45491

Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability

MEDIUM 6.2
NuGet

CVE-2026-46557

ImageMagick: Stack overflow in fx operation

MEDIUM 4.1
NuGet

CVE-2026-47165

ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model

MEDIUM 4.1
NuGet

CVE-2026-46693

ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

MEDIUM 5.1
NuGet

CVE-2026-45624

ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.

MEDIUM 5.5
NuGet

CVE-2026-46521

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

MEDIUM 5.3
NuGet

CVE-2026-45664

ImageMagick: Policy Bypass in MNG coder could

MEDIUM 4.0
NuGet

CVE-2026-46559

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

MEDIUM 5.1
NuGet

CVE-2026-42326

ImageMagick: Heap Buffer Over-Read in IPTC encoder

MEDIUM 5.3
NuGet

CVE-2026-45358

ImageMagick: Out-of-Bounds Read of a single byte in meta encoder

MEDIUM 5.3
NuGet

CVE-2026-45031

ImageMagick: Policy Bypass in PSD decoder

MEDIUM 5.7
NuGet

CVE-2026-45359

ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define

MEDIUM 5.4
NuGet

CVE-2026-46616

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

MEDIUM 4.6
NuGet

CVE-2026-46609

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

MEDIUM 5.3
NuGet

CVE-2026-40182

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

MEDIUM 5.5
NuGet

CVE-2018-1002206

Directory Traversal in SharpCompress

MEDIUM 6.3
NuGet

CVE-2022-24512

.NET Remote Code Execution Vulnerability

MEDIUM 6.5
NuGet

CVE-2026-44213

OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured

MEDIUM 5.3
NuGet

GHSA-92vj-hp7m-gwcj

Nerdbank.MessagePack has Inefficient CPU Computation

MEDIUM 5.3
NuGet

GHSA-qjvr-435c-5fjh

Nerdbank.MessagePack has a memory amplification DoS in collection deserialization

MEDIUM 5.7
NuGet

CVE-2026-47166

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server

MEDIUM 4.1
NuGet

CVE-2026-46692

ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

MEDIUM 6.2
NuGet

GHSA-jqq5-8px3-9m6m

ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix

MEDIUM 6.2
NuGet

CVE-2026-45785

OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle

MEDIUM 6.5
NuGet

CVE-2026-42191

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

MEDIUM 5.9
NuGet

CVE-2026-42348

OpAMP client reads unbounded HTTP response bodies

MEDIUM 6.2
NuGet

CVE-2026-41511

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

MEDIUM 5.3
NuGet

CVE-2026-42241

ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width

MEDIUM 6.2
NuGet

CVE-2026-40169

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

MEDIUM 4.7
NuGet

CVE-2025-62594

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

Ready to move

Start Securing

Free, no credit card | First findings in minutes