Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.2
NuGet

CVE-2026-46557

ImageMagick: Stack overflow in fx operation

MEDIUM 4.1
NuGet

CVE-2026-47165

ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model

MEDIUM 4.1
NuGet

CVE-2026-46693

ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

MEDIUM 5.1
NuGet

CVE-2026-45624

ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.

MEDIUM 5.5
NuGet

CVE-2026-46521

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

MEDIUM 5.3
NuGet

CVE-2026-45664

ImageMagick: Policy Bypass in MNG coder could

MEDIUM 6.2
NuGet

CVE-2026-46523

ImageMagick: Use-After-Free in MSL decoder.

MEDIUM 4.0
NuGet

CVE-2026-46559

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

MEDIUM 5.1
NuGet

CVE-2026-42326

ImageMagick: Heap Buffer Over-Read in IPTC encoder

MEDIUM 5.3
NuGet

CVE-2026-45358

ImageMagick: Out-of-Bounds Read of a single byte in meta encoder

MEDIUM 5.3
NuGet

CVE-2026-45031

ImageMagick: Policy Bypass in PSD decoder

MEDIUM 5.7
NuGet

CVE-2026-45359

ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define

MEDIUM 5.4
NuGet

CVE-2026-46616

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

MEDIUM 4.6
NuGet

CVE-2026-46609

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

MEDIUM 5.3
NuGet

CVE-2026-40182

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

MEDIUM 5.5
NuGet

CVE-2018-1002206

Directory Traversal in SharpCompress

MEDIUM 6.3
NuGet

CVE-2022-24512

.NET Remote Code Execution Vulnerability

MEDIUM 6.5
NuGet

CVE-2026-44213

OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured

MEDIUM 5.3
NuGet

GHSA-92vj-hp7m-gwcj

Nerdbank.MessagePack has Inefficient CPU Computation

MEDIUM 5.3
NuGet

GHSA-qjvr-435c-5fjh

Nerdbank.MessagePack has a memory amplification DoS in collection deserialization

MEDIUM 5.7
NuGet

CVE-2026-47166

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server

MEDIUM 4.1
NuGet

CVE-2026-46692

ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

MEDIUM 6.2
NuGet

GHSA-jqq5-8px3-9m6m

ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix

MEDIUM 6.2
NuGet

CVE-2026-45785

OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle

MEDIUM 6.5
NuGet

CVE-2026-42191

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

MEDIUM 5.9
NuGet

CVE-2026-42348

OpAMP client reads unbounded HTTP response bodies

MEDIUM 6.2
NuGet

CVE-2026-41511

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

MEDIUM 5.3
NuGet

CVE-2026-42241

ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width

MEDIUM 6.2
NuGet

CVE-2026-40169

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

MEDIUM 4.7
NuGet

CVE-2025-62594

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

MEDIUM 5.5
NuGet

CVE-2026-40183

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

MEDIUM 6.2
NuGet

CVE-2026-40312

ImageMagick has an off-by-one error in MSL decoder could result in crash

MEDIUM 5.5
NuGet

CVE-2026-23874

ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript

MEDIUM 5.9
NuGet

CVE-2026-44788

SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)

MEDIUM 5.3
NuGet

CVE-2026-41310

OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

MEDIUM 5.3
NuGet

CVE-2026-41484

OneCollector exporter reads unbounded HTTP response bodies

MEDIUM 5.9
NuGet

CVE-2026-41483

OpenTelemetry.Resources.Azure has an unbounded HTTP response body read

MEDIUM 5.9
NuGet

CVE-2026-33900

ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds

MEDIUM 4.3
NuGet

CVE-2026-40305

DNN: Force Friend Request Acceptance

MEDIUM 6.5
NuGet

CVE-2026-41319

MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade

MEDIUM 5.3
NuGet

CVE-2026-40021

Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters

MEDIUM 5.9
NuGet

CVE-2026-41078

OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path

MEDIUM 5.1
NuGet

CVE-2026-34238

ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds

MEDIUM 6.5
NuGet

CVE-2026-40306

DNN: Same HostGUID for all new installs

MEDIUM 5.3
NuGet

CVE-2026-40891

OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

MEDIUM 5.3
NuGet

CVE-2026-40894

OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

MEDIUM 5.9
NuGet

CVE-2026-41173

OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads

MEDIUM 5.3
NuGet

CVE-2026-33899

ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.

MEDIUM 5.5
NuGet

CVE-2026-33902

ImageMagick has a Stack Overflow via Recursive FX Expression Parsing

MEDIUM 5.5
NuGet

CVE-2026-33905

ImageMagick has an out-of-bounds read in sample operation

MEDIUM 5.5
NuGet

CVE-2026-40311

ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.

MEDIUM 5.5
NuGet

CVE-2026-40310

ImageMagick has a heap out-of-bounds write in JP2 encoder

MEDIUM 6.9
NuGet

GHSA-98cp-rj9f-6v5g

ImageMagick has has a stack-buffer-overflow in MNG encoder with oversized pallete

MEDIUM 5.1
NuGet

CVE-2026-33536

ImageMagick has an Out-of-bounds Write via InterpretImageFilename

MEDIUM 4.0
NuGet

CVE-2026-33535

ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction

MEDIUM 6.5
NuGet

GHSA-m2p3-hwv5-xpqw

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

MEDIUM 6.5
NuGet

GHSA-xw6w-9jjh-p9cr

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

MEDIUM 4.4
NuGet

CVE-2026-30935

ImageMagick has Heap Buffer Over-Read in BilateralBlurImage

MEDIUM 6.8
NuGet

CVE-2026-30931

ImageMagick has heap-based buffer overflow in UHDR encoder

MEDIUM 6.5
NuGet

CVE-2026-28493

ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder

Ready to move

Start Securing

Free, no credit card | First findings in minutes