CVE Vulnerability Database

Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-61867LOW2.9ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attac...
CVE-2026-61866HIGH7.5ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack...
CVE-2026-61865LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation...
CVE-2026-61864LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the...
CVE-2026-61863HIGH7.5ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem...
CVE-2026-61862LOW2.9ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed ...
CVE-2026-61860MEDIUM6.3ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati...
CVE-2026-61859MEDIUM4.8ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio...
CVE-2026-61464LOW1.8ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running...
CVE-2026-61457HIGH8.8The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media cont...
CVE-2026-61453MEDIUM6.1Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec...
CVE-2026-61452MEDIUM6.9The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where...
CVE-2026-61451CRITICAL9.6The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url fi...
CVE-2026-61449HIGH7.1Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in ...
CVE-2026-61446HIGH8.6PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo...
CVE-2026-61443HIGH8.6PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc...
CVE-2026-61440HIGH7.1PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members ...
CVE-2026-61438HIGH7.3PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due ...
CVE-2026-61436HIGH8.8PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta...
CVE-2026-61435HIGH8.8PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai...
CVE-2026-61433HIGH8.5PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP...
CVE-2026-61430HIGH8.5PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna...
CVE-2026-61427HIGH7.3PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio...
CVE-2026-60087MEDIUM6.9PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals ...
CVE-2026-60085HIGH8.7PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w...