ImageMagick Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for ImageMagick products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
3
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
ImageMagick KEVs Added by Year
3 ImageMagick KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2016-3718
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery... |
ImageMagick | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-3715
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
ImageMagick | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-3714
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before... |
ImageMagick | Confirmed | In CISA | 09 Sep 2024 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 1
- CWE-552 — Files or Directories Accessible to External Parties 1
- CWE-918 — Server-Side Request Forgery (SSRF) 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology