An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High
11 days ago

ImageMagick has a Format String Bug in InterpretImageFilename leads to arbitrary code execution GSA_kwCzR0hTQS05Y2NnLTZwancteDY0Nc4ABLbl

nuget Magick.NET-Q8-x86, Magick.NET-Q8-x64, Magick.NET-Q8-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-AnyCPU, Magick.NET-Q16-x86, Magick.NET-Q16-x64, Magick.NET-Q16-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-AnyCPU
High
12 days ago

imagemagick: integer overflows in MNG magnification GSA_kwCzR0hTQS1xcDI5LXd4cDUtd2g4Ms4ABLZ8

nuget Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-arm64, Magick.NET-Q16-x64, Magick.NET-Q16-x86, Magick.NET-Q8-AnyCPU, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-arm64, Magick.NET-Q8-x64, Magick.NET-Q8-x86
High
12 days ago

imagemagick: heap-buffer overflow read in MNG magnification with alpha GSA_kwCzR0hTQS1jamM4LWc5dzgtY2hmd84ABLZ6

nuget Magick.NET-Q8-x86, Magick.NET-Q8-x64, Magick.NET-Q8-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-AnyCPU, Magick.NET-Q16-x86, Magick.NET-Q16-x64, Magick.NET-Q16-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-AnyCPU
High
12 days ago

ImageMagick has a Stack Buffer Overflow in image.c GSA_kwCzR0hTQS1xaDNoLWo1NDUtaDhjOc4ABLZ2

nuget Magick.NET-Q8-x86, Magick.NET-Q8-x64, Magick.NET-Q8-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-AnyCPU, Magick.NET-Q16-x86, Magick.NET-Q16-x64, Magick.NET-Q16-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-AnyCPU
High
about 1 month ago

ImageMagick has XMP profile write that triggers hang due to unbounded loop GSA_kwCzR0hTQS12bWhoLThyeHEtZnA5Z84ABKdQ

nuget Magick.NET-Q16-HDRI-OpenMP-arm64, Magick.NET-Q16-HDRI-OpenMP-x64, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-HDRI-arm64, Magick.NET-Q16-HDRI-x64, Magick.NET-Q16-OpenMP-x86, Magick.NET-Q16-OpenMP-arm64, Magick.NET-Q16-OpenMP-x64, Magick.NET-Q16-x86, Magick.NET-Q16-arm64, Magick.NET-Q16-x64, Magick.NET-Q8-OpenMP-arm64, Magick.NET-Q8-OpenMP-x64, Magick.NET-Q8-x86, Magick.NET-Q8-arm64, Magick.NET-Q8-x64, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-AnyCPU, Magick.NET-Q8-AnyCPU

Filter by Severity

Filter by Ecosystem

Filter by Package

Microsoft.ChakraCore 234 tensorflow 122 tensorflow-gpu 119 tensorflow-cpu 115 magento/community-edition 81 moodle/moodle 61 org.jenkins-ci.main:jenkins-core 56 Django 49 com.fasterxml.jackson.core:jackson-databind 43 typo3/cms 42 dolibarr/dolibarr 34 Plone 33 drupal/core 33 librenms/librenms 32 org.apache.tomcat:tomcat 31 mlflow 30 pimcore/pimcore 30 apache-airflow 29 salt 29 github.com/rancher/rancher 29 drupal/drupal 29 typo3/cms-core 29 phpmyadmin/phpmyadmin 28 microweber/microweber 27 nokogiri 26 magento/project-community-edition 25 org.apache.struts:struts2-core 24 ansible 24 opencv-python 23 opencv-contrib-python 23 com.liferay.portal:release.portal.bom 23 org.apache.tomcat.embed:tomcat-embed-core 22 symfony/symfony 22 com.thoughtworks.xstream:xstream 22 com.jfinal:jfinal 21 django 20 org.jenkins-ci.plugins:script-security 20 matrix-synapse 20 thorsten/phpmyfaq 20 Pillow 19 com.liferay.portal:release.dxp.bom 19 pillow 18 pocketmine/pocketmine-mp 18 github.com/hashicorp/vault 18 rdiffweb 17 openssl-src 17 io.undertow:undertow-core 17 github.com/grafana/grafana 17 Microsoft.AspNetCore.App.Runtime.win-x64 17 gradio 17 Microsoft.AspNetCore.App.Runtime.win-x86 17 Microsoft.AspNetCore.App.Runtime.win-arm 16 parse-server 16 getgrav/grav 16 nilsteampassnet/teampass 15 keystone 15 github.com/hashicorp/consul 15 Microsoft.AspNetCore.App.Runtime.win-arm64 15 org.xwiki.platform:xwiki-platform-oldcore 15 open-webui 15 craftcms/cms 14 github.com/usememos/memos 14 Microsoft.NetCore.App.Runtime.win-arm 14 Microsoft.AspNetCore.App.Runtime.osx-x64 14 net.mingsoft:ms-mcms 14 org.keycloak:keycloak-core 14 Microsoft.AspNetCore.App.Runtime.linux-arm 14 centreon/centreon 14 Microsoft.NetCore.App.Runtime.win-x64 14 vyper 14 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 14 Microsoft.NetCore.App.Runtime.win-x86 14 Microsoft.AspNetCore.App.Runtime.linux-x64 14 Microsoft.NetCore.App.Runtime.win-arm64 14 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 14 shopware/platform 14 Microsoft.AspNetCore.App.Runtime.linux-arm64 14 mautic/core 13 mindsdb 13 silverstripe/framework 13 org.apache.solr:solr-core 13 apache-superset 13 rubygems-update 13 electron 13 golang.org/x/net 13 org.keycloak:keycloak-services 13 org.apache.openmeetings:openmeetings-parent 12 phpoffice/phpspreadsheet 12 phpoffice/phpexcel 12 shopware/core 12 baserproject/basercms 12 activerecord 12 directus 11 intelliants/subrion 11 gogs.io/gogs 11 cockpit-hq/cockpit 11 github.com/nats-io/nats-server/v2 11 next 11 froxlor/froxlor 11 actionpack 11 github.com/zitadel/zitadel 11 github.com/hashicorp/nomad 11 org.keycloak:keycloak-parent 11 laravel/framework 10 org.springframework.security:spring-security-core 10 nova 10 openmage/magento-lts 10 surrealdb 10 Microsoft.AspNetCore.App.Runtime.linux-musl-arm 10 github.com/traefik/traefik/v2 10 snipe/snipe-it 10 github.com/ollama/ollama 10 deno 10 github.com/argoproj/argo-cd 10 k8s.io/kubernetes 10 funadmin/funadmin 10 lollms 9 litellm 9 org.apache.hadoop:hadoop-main 9 ckb 9 zendframework/zendframework1 9 h2o 9 aim 9 org.apache.nifi:nifi 9 cobbler 9 github.com/ethereum/go-ethereum 9 Microsoft.NetCore.App.Runtime.osx-x64 9 Microsoft.NetCore.App.Runtime.osx-arm64 9 org.cloudfoundry.identity:cloudfoundry-identity-server 9 org.bouncycastle:bcprov-jdk14 9 Microsoft.NetCore.App.Runtime.linux-x64 9 Microsoft.NetCore.App.Runtime.linux-musl-x64 9 Microsoft.NetCore.App.Runtime.linux-musl-arm64 9 org.apache.tomcat:tomcat-catalina 9 org.apache.struts.xwork:xwork-core 9 Microsoft.NetCore.App.Runtime.linux-musl-arm 9 Microsoft.NetCore.App.Runtime.linux-arm64 9 Microsoft.NetCore.App.Runtime.linux-arm 9 rusqlite 9 neutron 9 mercurial 9 org.apache.geode:geode-core 9 smarty/smarty 8 org.eclipse.jetty:jetty-server 8 ai.h2o:h2o-core 8 org.bouncycastle:bcprov-jdk15 8 org.craftercms:crafter-studio 8 Microsoft.NETCore.App.Runtime.win-x86 8 october/system 8 github.com/docker/docker 8 plone 8 pyload-ng 8 rack 8 Microsoft.NETCore.App.Runtime.win-x64 8 cryptography 8 Microsoft.AspNetCore.App.Runtime.osx-arm64 8 phpbb/phpbb 8 org.jenkins-ci.plugins.workflow:workflow-cps 8 Microsoft.NETCore.App.Runtime.win-arm64 8 org.apache.tomcat:tomcat-coyote 8 github.com/argoproj/argo-cd/v2 8 yeswiki/yeswiki 8 composer/composer 8 moin 8 github.com/sylabs/singularity 8 tar 7 strapi 7 org.jenkins-ci.plugins.workflow:workflow-cps-global-lib 7 apollo-router 7 ryu 7 github.com/filebrowser/filebrowser/v2 7 golang.org/x/crypto 7 zendframework/zendframework 7 flowise 7 phpmailer/phpmailer 7 mantisbt/mantisbt 7 opencv-python-headless 7 OPCFoundation.NetStandard.Opc.Ua.Core 7 opencv-contrib-python-headless 7 symfony/security-http 7 magento/core 7 contao/core-bundle 7 org.elasticsearch:elasticsearch 7 k8s.io/ingress-nginx 7 symfony/security 7 org.springframework:spring-core 7 com.xuxueli:xxl-job 7 org.apache.inlong:manager-pojo 7 cakephp/cakephp 7 @strapi/strapi 7 DotNetNuke.Core 7 codeigniter4/framework 7 cn.hutool:hutool-core 7 contao/contao 6 label-studio 6 trytond 6 Magick.NET-Q16-HDRI-x86 6 org.springframework:spring-webmvc 6 istio.io/istio 6 Magick.NET-Q8-AnyCPU 6

Filter by Repository