8.6

CVSS3.1

CVE-2026-25965 - ImageMagick's policy bypass through path traversal allows reading restricted content despite secure…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypa…

📅 Published: Feb. 24, 2026, 1:20 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.

6.5

CVSS3.1

CVE-2026-25898 - Imagemagick Has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum`…

📅 Published: Feb. 24, 2026, 1:18 a.m. 🔄 Last Modified: April 18, 2026, 11 a.m.

6.5

CVSS3.1

CVE-2026-25897 - ImageMagick has heap overflow in sun decoder on 32-bit systems that can result in out of bounds wri…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions…

📅 Published: Feb. 24, 2026, 1:16 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.

5.3

CVSS3.1

CVE-2026-25799 - ImageMagick has Division-by-Zero in YUV sampling factor validation, which leads to crash

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting …

📅 Published: Feb. 24, 2026, 1:05 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.

5.3

CVSS3.1

CVE-2026-25798 - ImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted image

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image …

📅 Published: Feb. 24, 2026, 1:02 a.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

5.3

CVSS4.0

CVE-2026-3051 - DataLinkDC dinky Project Name GitRepository.java getProjectDir path traversal

A vulnerability has been found in DataLinkDC dinky up to 1.2.5. The affected element is the function getProjectDir of the file dinky-admin/src/main/java/org/dinky/utils/GitRepository.java of the component Project Name Handler. Such manipulation of the argument projectName leads to path traversal. T…

📅 Published: Feb. 24, 2026, 1:02 a.m. 🔄 Last Modified: April 18, 2026, 11:15 a.m.

5.1

CVSS4.0

CVE-2026-3050 - horilla-opensource horilla Leads global.js cross site scripting

A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The attack is possible to be carried out remotely. The exploit …

📅 Published: Feb. 24, 2026, 1:02 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.

5.7

CVSS3.1

CVE-2026-25797 - ImageMagick vulnerable to Code injection via PostScript header in ps coders

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker can provide a mali…

📅 Published: Feb. 24, 2026, 1:01 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.

5.8

CVSS3.1

CVE-2026-3099 - Libsoup: libsoup: authentication bypass via digest authentication replay attack

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentica…

📅 Published: Feb. 24, 2026, 1:01 a.m. 🔄 Last Modified: April 17, 2026, 10 a.m.

5.3

CVSS3.1

CVE-2026-25796 - ImageMagick has memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-r…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+…

📅 Published: Feb. 24, 2026, 12:57 a.m. 🔄 Last Modified: April 17, 2026, 4:15 p.m.
Total resulsts: 349182
Page 1475 of 34,919
« previous page » next page
Filters