5.3

CVSS3.1

CVE-2026-25795 - ImageMagick has NULL pointer dereference in ReadSFWImage after DestroyImageInfo (sfw.c)

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointe…

πŸ“… Published: Feb. 24, 2026, 12:54 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:08 p.m.

8.2

CVSS3.1

CVE-2026-25794 - ImageMagick has heap-buffer-overflow via signed integer overflow in `WriteUHDRImage` when writing U…

ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing a…

πŸ“… Published: Feb. 24, 2026, 12:53 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:05 p.m.

5.3

CVSS3.1

CVE-2026-25638 - ImageMagick has memory leak in msl encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasi…

πŸ“… Published: Feb. 24, 2026, 12:49 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:03 p.m.

5.3

CVSS3.1

CVE-2026-25637 - ImageMagick: Possible memory leak in ASHLAR encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allocated but never fre…

πŸ“… Published: Feb. 24, 2026, 12:48 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 2:32 p.m.

5.9

CVSS3.1

CVE-2026-27729 - Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments. On-demand rendered sites b…

πŸ“… Published: Feb. 24, 2026, 12:46 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:59 p.m.

7.6

CVSS3.1

CVE-2026-25802 - New API has Potential XSS in its MarkdownRenderer component

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>…

πŸ“… Published: Feb. 24, 2026, 12:42 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:58 p.m.

7.1

CVSS4.0

CVE-2026-25591 - New API has an SQL LIKE Wildcard Injection DoS via Token Search

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustio…

πŸ“… Published: Feb. 24, 2026, 12:41 a.m. πŸ”„ Last Modified: March 3, 2026, 5:22 p.m.

5.1

CVSS3.1

CVE-2026-25576 - ImageMagick: Out of bounds read in multiple coders read raw pixel data

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger…

πŸ“… Published: Feb. 24, 2026, 12:38 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 2:33 p.m.

6.9

CVSS4.0

CVE-2026-25545 - Astro has Full-Read SSRF in error rendering via Host: header injection

Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can re…

πŸ“… Published: Feb. 24, 2026, 12:37 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:53 p.m.

7.5

CVSS3.1

CVE-2026-24485 - ImageMagick: Infinite loop vulnerability when parsing a PCD file

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing …

πŸ“… Published: Feb. 24, 2026, 12:34 a.m. πŸ”„ Last Modified: Feb. 27, 2026, 2:34 p.m.
Total resulsts: 344821
Page 1042 of 34,483
Β« previous page Β» next page
Filters