CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-62946MEDIUM | ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit buildsImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27. CWE-190Jul 30, 2026 | CVSS5.1v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62363MEDIUM | ImageMagick: Heap Buffer Over-Write in fx operationImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27. CWE-787Jul 30, 2026 | CVSS5.0v3.1 | EPSS0.132% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62343MEDIUM | ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is providedImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. CWE-190Jul 29, 2026 | CVSS4.7v3.1 | EPSS0.124% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
ImageMagick: Heap Buffer Over-Write in X11 import with crafted window titleRunning an X11 import with a crafted window title can result in a heap buffer over-write. CWE-122Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specifiedAn invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in ICON decoder when allocation failsA memory leak will occur in the ICON decoder when an allocation fails. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory leak in VIFF encoder when allocation failsWhen an allocation fails in the VIFF encoder a memory leak will occus. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in MIFF encoder when allocaton failsA memory leak will occur in the MIFF encoder when an allocation fails. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in YUV decoder when opening of blob failsA memory leak will occur when a blob cannot be opened in the YUV decoder. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in TIFF encoder when an allocation failsWhen an allocation fails in the TIFF encoder a small memory leak will occur. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in JNG encoder when a blob could not be openedWhen a blob can not be opened a memory leak will occur when encoding a JNG file. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in hough lines operation when an operation failsWhen a specific operation fails in the hough lines operation a small memory leak will occur. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in color transformation to log colorspace when operation failsWhen transforming an image to the log colorspace a small memory leak happens when the operation fails. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.When a temporary file can not be created a small memory leak will happen in the TIFF encoder. CWE-401Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Information Disclosure when printing profiles with debug enabledWhen a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation failsWhen a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory. CWE-416Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Use-After-Free when freetype initialization failsWhen the freetype initialization fails the method does not exit and uses memory that was freed. CWE-416Jul 24, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Policy Bypass in script operation due to missing checksThe -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing checkDue to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Heap-use-after-free via XMP profile could result in a crashBecause of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219An incomplete fix of CVE-2026-49219 could result in a policy bypass. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ImageMagick: Policy Bypass possible with matrix-backed operationsMatrix bases operations like `-canny` are missing a check for allowed memory allocation that could result allocating more memory than allowed. | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-55597MEDIUM | ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of argumentsImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26. | CVSS5.5v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55595MEDIUM | ImageMagick: Infinite Loop in connected-components when providing invalid argumentsImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | CVSS4.7v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |