2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100637 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authentica... |
| CVE-2026-100636 | HIGH | 7.6 | — | Sep 26, 2026 | SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authe... |
| CVE-2026-100635 | MEDIUM | 5.9 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are is... |
| CVE-2026-100634 | MEDIUM | 4.7 | — | Sep 26, 2026 | SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the... |
| CVE-2026-100633 | MEDIUM | 6.5 | — | Sep 26, 2026 | SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensi... |
| CVE-2026-100632 | MEDIUM | 6.5 | — | Sep 26, 2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, Live... |
| CVE-2026-100631 | HIGH | 7.5 | — | Sep 26, 2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-al... |
| CVE-2026-100630 | MEDIUM | 5.4 | — | Sep 26, 2026 | AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an i... |
| CVE-2026-100629 | MEDIUM | 5.5 | — | Sep 26, 2026 | Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id... |
| CVE-2026-100628 | MEDIUM | 4.3 | — | Sep 26, 2026 | capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API key... |
| CVE-2026-100627 | HIGH | 8.1 | — | Sep 26, 2026 | Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle... |
| CVE-2026-100626 | MEDIUM | 4.3 | — | Sep 26, 2026 | capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that a... |
| CVE-2026-100625 | HIGH | 7.1 | — | Sep 26, 2026 | Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that auth... |
| CVE-2026-100624 | MEDIUM | 5.4 | — | Sep 26, 2026 | Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy ... |
| CVE-2026-100623 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's ... |
| CVE-2026-100622 | HIGH | 7.5 | — | Sep 26, 2026 | capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file rea... |
| CVE-2026-100621 | MEDIUM | 4.3 | — | Sep 26, 2026 | Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch ... |
| CVE-2026-100620 | LOW | 3.8 | — | Sep 26, 2026 | Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onb... |
| CVE-2026-100619 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy... |
| CVE-2026-100618 | HIGH | 8.5 | — | Sep 26, 2026 | Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a ... |
| CVE-2026-100617 | HIGH | 8.8 | — | Sep 26, 2026 | Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing ... |
| CVE-2026-100616 | MEDIUM | 5.5 | — | Sep 26, 2026 | capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security ... |
| CVE-2026-100615 | HIGH | 8.8 | — | Sep 26, 2026 | Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager ... |
| CVE-2026-100614 | HIGH | 8.8 | — | Sep 26, 2026 | Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image ... |
| CVE-2026-100613 | MEDIUM | 5.3 | — | Sep 26, 2026 | capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now