Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 24 February 2026
RSS259 vulnerabilities published on 24 February 2026
Severity:
free5GC User Data Repository (UDR) Leaks Error Details
CVE-2026-27643
The free5GC User Data Repository (UDR) in versions up to 1.4.1 may leak sensitive error details to remote clients, potentially helping attackers to identify network services. This affects all free5GC ...
6.6
ImageMagick fails to sanitize PostScript input, allowing code injection
DEBIAN-CVE-2026-25797
ImageMagick's PostScript feature doesn't properly check for malicious code, which can be executed by a printer or viewer when processing a file. This can lead to unauthorized actions on the system. Up...
5.3
ImageMagick Memory Leak in Image Editing Software
DEBIAN-CVE-2026-25638
A memory leak in ImageMagick can cause system issues if exploited. This affects users who use outdated versions of ImageMagick, particularly those who frequently edit large images. Update to version 7...
5.3
Outdated ImageMagick Allows Memory Exhaustion by Malicious Images
DEBIAN-CVE-2026-25637
ImageMagick versions before 7.1.2-15 can be exploited by a malicious image that causes the software to run out of memory. This could lead to image processing crashing or slowing down. To fix, update t...
5.3
ImageMagick Fails to Validate SVG Conversions, Crashing Server
DEBIAN-CVE-2026-24484
ImageMagick, a popular image editing software, fails to properly handle certain SVG conversions, which could cause a denial-of-service (crash) on affected servers. This issue affects older versions of...
5.3
free5GC User Data Repository Leaks Error Details to Attackers
CVE-2025-69253
Versions of free5GC's User Data Repository up to 1.4.1 may allow attackers to gather information about your network's internal workings. This could help them launch more targeted attacks. To fix this,...
6.6
ImageMagick crashes when loading certain images
CVE-2026-25799
GHSA-543g-8grm-9cw6
ImageMagick, used for image editing, can crash if it encounters a specific type of image. This is not a security issue that could allow someone to steal or damage your data, but it will cause the prog...
5.3
ImageMagick can crash when opening a malicious image file
CVE-2026-25798
GHSA-p863-5fgm-rgq4
A security issue in ImageMagick can cause a program to crash if it's given a specially crafted image file. This can lead to a denial of service. To protect against this, update to version 7.1.2-15 or ...
5.3
ImageMagick Memory Leak Can Cause Denial of Service
CVE-2026-25796
GHSA-g2pr-qxjg-7r2w
The free ImageMagick software may run out of memory if it processes a large number of images, potentially causing it to stop working. This is due to a weakness in how it handles certain image files. U...
5.3
ImageMagick Crashes When Creating Temporary Files
CVE-2026-25795
GHSA-p33r-fqw2-rqmm
ImageMagick, a popular image editing software, can crash when it fails to create temporary files. This happens in certain versions of the software, but it's been fixed in the latest updates. To stay s...
5.3
ImageMagick Memory Leak in Older Versions Can Cause Slowdowns
CVE-2026-25638
GHSA-gxcx-qjqp-8vjw
ImageMagick, a popular image editing software, has a memory leak in older versions. This can cause the software to become slow or unresponsive over time. Update to version 7.1.2-15 or 6.9.13-40 to fix...
5.3
ImageMagick: Malicious images can crash the program or slow it down
CVE-2026-25637
GHSA-gm37-qx7w-p258
ImageMagick, a popular image editing software, has a bug that can cause it to consume all available memory when processing a specially crafted image. This can lead to the program crashing or slowing d...
5.3
ImageMagick: Converting certain image files can crash the program
CVE-2026-24484
GHSA-wg3g-gvx5-2pmv
If you use ImageMagick to convert certain image files, it could crash or freeze. This is because of a bug in older versions of the software. Update to the latest version to fix the issue.
5.3
Free5GC UDM exposes internal system details to remote attackers
CVE-2025-69251
Free5GC's Unified Data Management (UDM) service allows remote attackers to inject malicious characters into system inputs, potentially exposing internal details and aiding in identifying the system's ...
6.6
ImageMagick: Malicious images can read sensitive memory
CVE-2026-25576
GHSA-jv4p-gjwq-9r2j
ImageMagick, a popular image editing software, has a security issue that could allow an attacker to access sensitive memory. If you're using an outdated version of ImageMagick, an attacker could explo...
5.1
Pimcore: Unsecured Filter Input Allows SQL Injection
CVE-2026-27461
GHSA-vxg3-v4p6-f3fp
Pimcore's dependency listing endpoints are vulnerable to SQL injection attacks, allowing an attacker with admin access to execute malicious SQL code. This can lead to sensitive data exposure or system...
6.9
SonicOS Firewall Can Crash After Authentication
CVE-2026-0402
A security issue in SonicOS firewalls can allow an attacker to crash the device after a user has logged in. This could cause disruptions to network services. To mitigate this, update your SonicOS fire...
4.9
SonicOS Firewall Crashes Remotely After Authentication
CVE-2026-0401
A flaw in SonicOS can allow an attacker to intentionally crash a firewall after they have logged in. This could disrupt network access and require a system reboot. Users should update their SonicOS so...
4.9
SonicOS Firewall Can Crash from Remote Attack
CVE-2026-0400
A security weakness in SonicOS software, used in firewalls, could allow a remote attacker to crash the firewall remotely, disrupting network security. This is a concern because it could leave a networ...
4.9
SonicOS Management Interface Can Be Crashed by Malicious Input
CVE-2026-0399
The SonicOS management interface has a security weakness that could allow an attacker to cause the system to crash or behave unexpectedly if they send a specially crafted input to the affected API end...
4.9
Zyxel VMG3625-T50B and WX3100-T0 routers: Denial of Service via Malicious Wake-on-LAN Request
CVE-2025-11848
An attacker with administrator privileges can crash the router by sending a specially crafted request, causing it to become unavailable. This affects the Wake-on-LAN feature in two specific router mod...
4.9
Zyxel VMG3625-T50B and WX3100-T0 Firmware Denial-of-Service Risk
CVE-2025-11847
A specially crafted HTTP request can crash the IP settings program of these Zyxel routers, causing them to stop working temporarily. This requires an attacker to be logged in with administrative privi...
4.9
Zyxel Routers: Administrator Privilege Required to Crash Device
CVE-2025-11846
Some Zyxel routers can crash if an attacker with admin access sends a special request. This can be done by an authorized person with malicious intent, not by hacking into the router. To fix this, upda...
4.9
Zyxel VMG3625-T50B and WX3100-T0 firmware: DoS via crafted HTTP request
CVE-2025-11845
If an attacker with admin access sends a specially crafted HTTP request, it can cause a Zyxel VMG3625-T50B or WX3100-T0 router to become unresponsive, making it unavailable for use. This is a serious ...
4.9
GetSimpleCMS CE 3.3.16: Stored XSS in Theme to Components
CVE-2026-26351
A critical security risk exists in GetSimpleCMS Community Edition 3.3.16. An attacker who has administrative access can inject malicious code into the CMS, allowing them to take control of the site an...
4.8