2026 CVE Vulnerabilities
56,979 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61867 | LOW | 2.9 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attac... |
| CVE-2026-61866 | HIGH | 7.5 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack... |
| CVE-2026-61865 | LOW | 2.9 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation... |
| CVE-2026-61864 | LOW | 2.9 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the... |
| CVE-2026-61863 | HIGH | 7.5 | 0.1% | Jul 15, 2026 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem... |
| CVE-2026-61862 | LOW | 2.9 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed ... |
| CVE-2026-61860 | MEDIUM | 6.3 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati... |
| CVE-2026-61859 | MEDIUM | 4.8 | 0.1% | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio... |
| CVE-2026-61464 | LOW | 1.8 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running... |
| CVE-2026-61457 | HIGH | 8.8 | — | Jul 15, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media cont... |
| CVE-2026-61453 | MEDIUM | 6.1 | — | Jul 15, 2026 | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec... |
| CVE-2026-61452 | MEDIUM | 6.9 | — | Jul 15, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where... |
| CVE-2026-61451 | CRITICAL | 9.6 | — | Jul 15, 2026 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url fi... |
| CVE-2026-61449 | HIGH | 7.1 | — | Jul 15, 2026 | Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in ... |
| CVE-2026-61446 | HIGH | 8.6 | — | Jul 15, 2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo... |
| CVE-2026-61443 | HIGH | 8.6 | — | Jul 15, 2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc... |
| CVE-2026-61440 | HIGH | 7.1 | 0.2% | Jul 15, 2026 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members ... |
| CVE-2026-61438 | HIGH | 7.3 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due ... |
| CVE-2026-61436 | HIGH | 8.8 | — | Jul 15, 2026 | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta... |
| CVE-2026-61435 | HIGH | 8.8 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai... |
| CVE-2026-61433 | HIGH | 8.5 | — | Jul 15, 2026 | PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP... |
| CVE-2026-61430 | HIGH | 8.5 | — | Jul 15, 2026 | PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna... |
| CVE-2026-61427 | HIGH | 7.3 | 0.3% | Jul 15, 2026 | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio... |
| CVE-2026-60087 | MEDIUM | 6.9 | — | Jul 15, 2026 | PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals ... |
| CVE-2026-60085 | HIGH | 8.7 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now