Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 226–250 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-61864 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. |
| CVE-2026-61863 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small … |
| CVE-2026-61862 | LOW | Patched | 2.9 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is n… |
| CVE-2026-61860 | LOW | Patched | 3.7 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to … |
| CVE-2026-61859 | LOW | Patched | 3.3 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows… |
| CVE-2026-61464 | LOW | Patched | 1.8 | 2026-07-15 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which ca… |
| CVE-2026-61457 | HIGH | Patched | 8.8 | 2026-07-15 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension()… |
| CVE-2026-61453 | MEDIUM | Patched | 6.1 | 2026-07-15 | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig process… |
| CVE-2026-61452 | MEDIUM | Patched | 5.3 | 2026-07-15 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID)… |
| CVE-2026-61451 | CRITICAL | Patched | 9.6 | 2026-07-15 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoin… |
| CVE-2026-61449 | MEDIUM | Patched | 6.5 | 2026-07-15 | Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each en… |
| CVE-2026-61446 | HIGH | Patched | 8.4 | 2026-07-15 | PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from p… |
| CVE-2026-61443 | HIGH | Patched | 8.1 | 2026-07-15 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers… |
| CVE-2026-61440 | MEDIUM | Patched | 6.5 | 2026-07-15 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remov… |
| CVE-2026-61438 | HIGH | Patched | 7.3 | 2026-07-15 | PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script st… |
| CVE-2026-61436 | HIGH | Patched | 8.6 | 2026-07-15 | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers ca… |
| CVE-2026-61435 | HIGH | Patched | 8.2 | 2026-07-15 | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=… |
| CVE-2026-61433 | HIGH | Patched | 7.8 | 2026-07-15 | PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python exp… |
| CVE-2026-61430 | HIGH | Patched | 8.5 | 2026-07-15 | PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection… |
| CVE-2026-61427 | HIGH | Patched | 7.3 | 2026-07-15 | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Aut… |
| CVE-2026-60087 | MEDIUM | Patched | 6.1 | 2026-07-15 | PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attac… |
| CVE-2026-60085 | HIGH | Patched | 7.5 | 2026-07-15 | PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_import… |
| CVE-2026-59259 | MEDIUM | Patched | 6.5 | 2026-07-15 | n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation … |
| CVE-2026-59254 | NONE | Patched | — | 2026-07-15 | n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. A… |
| CVE-2026-59236 | NONE | Patched | — | 2026-07-15 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.… |