Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-6VXP-GFWF-HCR9LowMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.GHSA-HWF3-R46V-5GGXLowMagick.NET-Q16-AnyCPU: ImageMagick: Information Disclosure when printing profiles with debug enabledGHSA-QVXH-PRVR-85W2LowMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation failsGHSA-6JWG-7Q3P-5FQMLowMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free when freetype initialization failsGHSA-VGHG-5JRG-2398LowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in script operation due to missing checks GHSA-V3J6-27VC-7PW2LowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing checkGHSA-QH5G-Q395-CX4JLowMagick.NET-Q16-AnyCPU: ImageMagick: Heap-use-after-free via XMP profile could result in a crashGHSA-HC76-7MPC-QJQHMediumMagick.NET-Q16-AnyCPU: ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797GHSA-56M6-8Q75-F2RWMediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219GHSA-RVHP-75F6-9JQHLowMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass possible with matrix-backed operationsGHSA-4W2J-M93H-CJ5JHighquinn-proto: Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyCVE-2026-55685Highreact-router: React Router: Unauthenticated Denial of Service via Inefficient Route MatchingCVE-2026-55628MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in concatenate operation due to missing checksCVE-2026-55597MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of argumentsCVE-2026-55595MediumMagick.NET-Q16-AnyCPU: ImageMagick: Infinite Loop in connected-components when providing invalid argumentsCVE-2026-55594MediumMagick.NET-Q16-AnyCPU: ImageMagick: Stack Overflow in MVG decoder due to missing depth check.CVE-2026-55575Highliquidjs: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforceCVE-2026-55510MediumMagick.NET-Q16-AnyCPU: ImageMagick: Use-After-Free in crafted 8BIM when identifying an imageCVE-2026-54673Highbuilder-util-runtime: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`CVE-2026-54672Highapp-builder-lib: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`CVE-2026-54696Lowjson: Ruby json: JSON generator heap buffer overflow when streaming to an IOCVE-2026-55223Mediumcom.mchange:c3p0: c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgetsCVE-2026-53669Mediumreact-router: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)CVE-2026-53668Mediumreact-router-dom: React Router: Open redirect leading to XSSCVE-2026-53667Mediumreact-router: React Router: RSCErrorHandler Missing Protocol Validation (XSS)

Stop the waste.
Protect your environment with Kodem.