2026 CVE Vulnerabilities
57,013 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61465 | MEDIUM | 6.5 | 0.2% | Jul 11, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed op... |
| CVE-2026-61454 | HIGH | 8.7 | 0.2% | Jul 11, 2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFI... |
| CVE-2026-61448 | LOW | 2.1 | 0.2% | Jul 11, 2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and... |
| CVE-2026-61447 | CRITICAL | 10 | 0.5% | Jul 11, 2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-... |
| CVE-2026-61445 | CRITICAL | 9.9 | 0.5% | Jul 11, 2026 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due... |
| CVE-2026-61442 | HIGH | 7.1 | 0.3% | Jul 11, 2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for ... |
| CVE-2026-61439 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults ... |
| CVE-2026-61429 | HIGH | 8.5 | 0.2% | Jul 11, 2026 | PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th... |
| CVE-2026-61428 | HIGH | 7.3 | 0.2% | Jul 11, 2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attacke... |
| CVE-2026-61426 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme... |
| CVE-2026-60090 | CRITICAL | 9.8 | 0.4% | Jul 11, 2026 | PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowled... |
| CVE-2026-60088 | MEDIUM | 6.8 | 0.1% | Jul 11, 2026 | PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f... |
| CVE-2026-56763 | MEDIUM | 6.3 | 0.2% | Jul 11, 2026 | Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na... |
| CVE-2026-56372 | CRITICAL | 9.1 | 0.1% | Jul 11, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers... |
| CVE-2026-56303 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function m... |
| CVE-2026-56296 | MEDIUM | 6.9 | 0.2% | Jul 11, 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that ret... |
| CVE-2026-56240 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o... |
| CVE-2026-57828 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoc... |
| CVE-2026-57827 | CRITICAL | 9.8 | 0.3% | Jul 11, 2026 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFi... |
| CVE-2026-1359 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2026-9282 | HIGH | 7.5 | 0.7% | Jul 11, 2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4... |
| CVE-2026-9017 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve... |
| CVE-2026-6939 | HIGH | 7.2 | 0.3% | Jul 11, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app... |
| CVE-2026-6801 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2026-4661 | HIGH | 7.5 | 0.3% | Jul 11, 2026 | The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now