2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-100646HIGH8.1SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authen...
CVE-2026-100645HIGH8SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database re...
CVE-2026-100644HIGH7.5SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath para...
CVE-2026-100643HIGH8SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing a...
CVE-2026-100642HIGH7.6SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-scree...
CVE-2026-100641HIGH8SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager l...
CVE-2026-100639HIGH8.8SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutt...
CVE-2026-100638HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authent...
CVE-2026-100637HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authentica...
CVE-2026-100636HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authe...
CVE-2026-100631HIGH7.5Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-al...
CVE-2026-100627HIGH8.1Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle...
CVE-2026-100625HIGH7.1Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that auth...
CVE-2026-100623HIGH8.8Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's ...
CVE-2026-100622HIGH7.5capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file rea...
CVE-2026-100619HIGH8.8Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy...
CVE-2026-100618HIGH8.5Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a ...
CVE-2026-100617HIGH8.8Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing ...
CVE-2026-100615HIGH8.8Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager ...
CVE-2026-100614HIGH8.8Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image ...
CVE-2026-100612HIGH7.2Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table....
CVE-2026-100610HIGH7.5Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permis...
CVE-2026-100608HIGH8.3Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode w...
CVE-2026-100607HIGH7.7Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifi...
CVE-2026-100606HIGH7.7Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login pat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now