2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100637HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authentica...
CVE-2026-100636HIGH7.6SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authe...
CVE-2026-100635MEDIUM5.9SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are is...
CVE-2026-100634MEDIUM4.7SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the...
CVE-2026-100633MEDIUM6.5SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensi...
CVE-2026-100632MEDIUM6.5Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, Live...
CVE-2026-100631HIGH7.5Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-al...
CVE-2026-100630MEDIUM5.4AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an i...
CVE-2026-100629MEDIUM5.5Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id...
CVE-2026-100628MEDIUM4.3capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API key...
CVE-2026-100627HIGH8.1Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle...
CVE-2026-100626MEDIUM4.3capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that a...
CVE-2026-100625HIGH7.1Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that auth...
CVE-2026-100624MEDIUM5.4Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy ...
CVE-2026-100623HIGH8.8Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's ...
CVE-2026-100622HIGH7.5capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file rea...
CVE-2026-100621MEDIUM4.3Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch ...
CVE-2026-100620LOW3.8Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onb...
CVE-2026-100619HIGH8.8Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy...
CVE-2026-100618HIGH8.5Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a ...
CVE-2026-100617HIGH8.8Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing ...
CVE-2026-100616MEDIUM5.5capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security ...
CVE-2026-100615HIGH8.8Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager ...
CVE-2026-100614HIGH8.8Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image ...
CVE-2026-100613MEDIUM5.3capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now