6.2

CVSS3.1

CVE-2026-25971 - ImageMagick's MSL: Stack overflow in ProcessMSLScript

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

📅 Published: Feb. 24, 2026, 1:39 a.m. 🔄 Last Modified: April 18, 2026, 6 p.m.

4.9

CVSS3.1

CVE-2025-11846 -

A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denia…

📅 Published: Feb. 24, 2026, 1:37 a.m. 🔄 Last Modified: Feb. 25, 2026, 6:14 p.m.

5.3

CVSS3.1

CVE-2026-25970 - ImageMagick SIXEL Decoder Has Signed Integer Overflow, Leading to Memory Corruption

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a mal…

📅 Published: Feb. 24, 2026, 1:35 a.m. 🔄 Last Modified: April 18, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2026-25969 - ImageMagick has Memory Leak in coders/ashlar.c

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a structure. However, when an exception is thrown, the allocated memory is not properly released, re…

📅 Published: Feb. 24, 2026, 1:33 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-3053 - DataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authentication

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch…

📅 Published: Feb. 24, 2026, 1:32 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3052 - DataLinkDC dinky Flink Proxy Controller FlinkProxyController.java proxyUba server-side request forg…

A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file dinky-admin/src/main/java/org/dinky/controller/FlinkProxyController.java of the component Flink Proxy Controller. Performing a manipulation results in server-side request forgery. It…

📅 Published: Feb. 24, 2026, 1:32 a.m. 🔄 Last Modified: April 16, 2026, 4:45 p.m.

7.4

CVSS3.1

CVE-2026-25968 - ImageMagick has MSL attribute stack buffer overflow that leads to out of bounds write.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions…

📅 Published: Feb. 24, 2026, 1:30 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

4.9

CVSS3.1

CVE-2025-11845 -

A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a…

📅 Published: Feb. 24, 2026, 1:30 a.m. 🔄 Last Modified: Feb. 25, 2026, 6:10 p.m.

7.4

CVSS3.1

CVE-2026-25967 - ImageMagick has stack buffer overflow in FTXT reader via oversized integer field

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a stack-based buffer overflow exists in the ImageMagick FTXT image reader. A crafted FTXT file can cause out-of-bounds writes on the stack, leading to a crash. Version 7.1.2-15 …

📅 Published: Feb. 24, 2026, 1:29 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

5.9

CVSS3.1

CVE-2026-25966 - ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to std…

ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd:<n> pseudo-filenames (e.g., fd:0, fd:1). Prior to vers…

📅 Published: Feb. 24, 2026, 1:27 a.m. 🔄 Last Modified: April 18, 2026, 11 a.m.
Total resulsts: 349182
Page 1474 of 34,919
« previous page » next page
Filters