Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

CWE-190Jul 30, 2026
CVSS5.1v3.1EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Heap Buffer Over-Write in fx operation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

CWE-787Jul 30, 2026
CVSS5.0v3.1EPSS0.132%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CWE-190Jul 29, 2026
CVSS4.7v3.1EPSS0.124%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title

Running an X11 import with a crafted window title can result in a heap buffer over-write.

CWE-122Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified

An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in ICON decoder when allocation fails

A memory leak will occur in the ICON decoder when an allocation fails.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory leak in VIFF encoder when allocation fails

When an allocation fails in the VIFF encoder a memory leak will occus.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in MIFF encoder when allocaton fails

A memory leak will occur in the MIFF encoder when an allocation fails.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in YUV decoder when opening of blob fails

A memory leak will occur when a blob cannot be opened in the YUV decoder.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in TIFF encoder when an allocation fails

When an allocation fails in the TIFF encoder a small memory leak will occur.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in JNG encoder when a blob could not be opened

When a blob can not be opened a memory leak will occur when encoding a JNG file.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in hough lines operation when an operation fails

When a specific operation fails in the hough lines operation a small memory leak will occur.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

When transforming an image to the log colorspace a small memory leak happens when the operation fails.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.

When a temporary file can not be created a small memory leak will happen in the TIFF encoder.

CWE-401Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Information Disclosure when printing profiles with debug enabled

When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.

CWE-125CWE-193Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails

When a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory.

CWE-416Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Use-After-Free when freetype initialization fails

When the freetype initialization fails the method does not exit and uses memory that was freed.

CWE-416Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Policy Bypass in script operation due to missing checks

The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.

CWE-284CWE-59Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.

CWE-59CWE-862Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.

CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.

CWE-116CWE-79Jul 24, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

An incomplete fix of CVE-2026-49219 could result in a policy bypass.

CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Policy Bypass possible with matrix-backed operations

Matrix bases operations like `-canny` are missing a check for allowed memory allocation that could result allocating more memory than allowed.

CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

CWE-682CWE-787Jul 1, 2026
CVSS5.5v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick: Infinite Loop in connected-components when providing invalid arguments

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CWE-400CWE-835Jul 1, 2026
CVSS4.7v3.1EPSS0.09%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX