2026 CVE Vulnerabilities

56,979 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61867LOW2.9ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attac...
CVE-2026-61866HIGH7.5ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack...
CVE-2026-61865LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation...
CVE-2026-61864LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the...
CVE-2026-61863HIGH7.5ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem...
CVE-2026-61862LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed ...
CVE-2026-61860MEDIUM6.3ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati...
CVE-2026-61859MEDIUM4.8ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio...
CVE-2026-61464LOW1.8ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running...
CVE-2026-61457HIGH8.8The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media cont...
CVE-2026-61453MEDIUM6.1Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec...
CVE-2026-61452MEDIUM6.9The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where...
CVE-2026-61451CRITICAL9.6The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url fi...
CVE-2026-61449HIGH7.1Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in ...
CVE-2026-61446HIGH8.6PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo...
CVE-2026-61443HIGH8.6PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc...
CVE-2026-61440HIGH7.1PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members ...
CVE-2026-61438HIGH7.3PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due ...
CVE-2026-61436HIGH8.8PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta...
CVE-2026-61435HIGH8.8PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai...
CVE-2026-61433HIGH8.5PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP...
CVE-2026-61430HIGH8.5PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna...
CVE-2026-61427HIGH7.3PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio...
CVE-2026-60087MEDIUM6.9PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals ...
CVE-2026-60085HIGH8.7PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now