Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-65829
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
CVE-2026-81868
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
CVE-2026-75523
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
CVE-2026-50659
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
CVE-2026-62363
ImageMagick: Heap Buffer Over-Write in fx operation
CVE-2026-48796
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
CVE-2026-46523
ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-33535
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
CVE-2026-33536
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
CVE-2026-40182
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVE-2024-55488
Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting
CVE-2026-46557
ImageMagick: Stack overflow in fx operation
CVE-2026-45491
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
CVE-2026-40183
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
CVE-2026-40312
ImageMagick has an off-by-one error in MSL decoder could result in crash
CVE-2026-40169
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
CVE-2026-40891
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVE-2026-28493
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
CVE-2026-40894
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVE-2026-30931
ImageMagick has heap-based buffer overflow in UHDR encoder
CVE-2026-42191
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-30935
ImageMagick has Heap Buffer Over-Read in BilateralBlurImage
CVE-2026-25637
ImageMagick: Possible memory leak in ASHLAR encoder
CVE-2026-25969
Image Magick has a Memory Leak in coders/ashlar.c
CVE-2025-55248
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
CVE-2026-22770
ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails
CVE-2025-68618
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
CVE-2026-23874
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
CVE-2025-68950
ImageMagick's failure to limit MVG mutual causes Stack Overflow
CVE-2025-62594
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
CVE-2025-9708
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
CVE-2025-49015
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
CVE-2025-27513
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
CVE-2024-41132
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
CVE-2024-39677
NHibernate SQL injection vulnerability in discriminator mappings, static fields referenced in HQL, and some utilities
CVE-2024-29035
Blind SSRF Leads to Port Scan by using Webhooks
CVE-2024-32035
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
GHSA-8g9c-28fc-mcx2
Duplicate Advisory: Microsoft Identity Denial of service vulnerability
GHSA-gv85-xg33-553c
Duplicate Advisory: ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS
CVE-2023-48313
DOM-XSS on Backoffice login screen.
CVE-2024-35218
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
CVE-2026-23952
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
CVE-2024-32028
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
CVE-2019-9648
CoreFTP Directory Traversal
CVE-2020-9472
Unrestricted Upload of File with Dangerous Type in Umbraco CMS
CVE-2020-29454
Incorrect permission enforcement in UmbracoCms
CVE-2023-44390
HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content
CVE-2024-34071
Umbraco CMS Open Redirect Bypass Protection
CVE-2024-32036
SixLabors.ImageSharp vulnerable to data leakage
CVE-2020-26293
XSS in HtmlSanitizer
CVE-2020-5811
Authenticated path traversal in Umbraco CMS
CVE-2020-5234
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
CVE-2018-1002206
Directory Traversal in SharpCompress
CVE-2020-11005
Internal NCryptDecrypt method could be used externally from WindowsHello library.
CVE-2020-5268
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
CVE-2018-1002205
DotNetZip Zip-Slip Vulnerability
CVE-2026-69304
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
GHSA-v3f6-m9j2-437p
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
CVE-2026-62900
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
CVE-2026-62902
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Ready to move
Start Securing
Free, no credit card | First findings in minutes