2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100646 | HIGH | 8.1 | — | Sep 26, 2026 | SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authen... |
| CVE-2026-100645 | HIGH | 8 | — | Sep 26, 2026 | SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database re... |
| CVE-2026-100644 | HIGH | 7.5 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath para... |
| CVE-2026-100643 | HIGH | 8 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing a... |
| CVE-2026-100642 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-scree... |
| CVE-2026-100641 | HIGH | 8 | — | Sep 26, 2026 | SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager l... |
| CVE-2026-100639 | HIGH | 8.8 | — | Sep 26, 2026 | SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutt... |
| CVE-2026-100638 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authent... |
| CVE-2026-100637 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authentica... |
| CVE-2026-100636 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authe... |
| CVE-2026-100631 | HIGH | 7.5 | — | Sep 26, 2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-al... |
| CVE-2026-100627 | HIGH | 8.1 | — | Sep 26, 2026 | Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle... |
| CVE-2026-100625 | HIGH | 7.1 | — | Sep 26, 2026 | Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that auth... |
| CVE-2026-100623 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's ... |
| CVE-2026-100622 | HIGH | 7.5 | — | Sep 26, 2026 | capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file rea... |
| CVE-2026-100619 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy... |
| CVE-2026-100618 | HIGH | 8.5 | — | Sep 26, 2026 | Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a ... |
| CVE-2026-100617 | HIGH | 8.8 | — | Sep 26, 2026 | Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing ... |
| CVE-2026-100615 | HIGH | 8.8 | — | Sep 26, 2026 | Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager ... |
| CVE-2026-100614 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image ... |
| CVE-2026-100612 | HIGH | 7.2 | — | Sep 26, 2026 | Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table.... |
| CVE-2026-100610 | HIGH | 7.5 | — | Sep 26, 2026 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permis... |
| CVE-2026-100608 | HIGH | 8.3 | — | Sep 26, 2026 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode w... |
| CVE-2026-100607 | HIGH | 7.7 | — | Sep 26, 2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifi... |
| CVE-2026-100606 | HIGH | 7.7 | — | Sep 26, 2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login pat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now