Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-100639 HIGH 8.8 SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing … Sep 26, 2026
CVE-2026-100638 HIGH 7.6 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files … Sep 26, 2026
CVE-2026-100637 HIGH 7.6 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers … Sep 26, 2026
CVE-2026-100636 HIGH 7.6 SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside … Sep 26, 2026
CVE-2026-100635 MEDIUM 5.9 SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP … Sep 26, 2026
CVE-2026-100634 MEDIUM 4.7 SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores … Sep 26, 2026
CVE-2026-100633 MEDIUM 6.5 SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied … Sep 26, 2026
CVE-2026-100632 MEDIUM 6.5 Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission … Sep 26, 2026
CVE-2026-100631 HIGH 7.5 Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication … Sep 26, 2026
CVE-2026-100630 MEDIUM 5.4 AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission … Sep 26, 2026
CVE-2026-100629 MEDIUM 5.5 Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does … Sep 26, 2026
CVE-2026-100628 MEDIUM 4.3 capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply … Sep 26, 2026
CVE-2026-100627 HIGH 8.1 Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and … Sep 26, 2026
CVE-2026-100626 MEDIUM 4.3 capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply … Sep 26, 2026
CVE-2026-100625 HIGH 7.1 Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and … Sep 26, 2026
CVE-2026-100624 MEDIUM 5.4 Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, … Sep 26, 2026
CVE-2026-100623 HIGH 8.8 Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org … Sep 26, 2026
CVE-2026-100622 HIGH 7.5 capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles … Sep 26, 2026
CVE-2026-100621 MEDIUM 4.3 Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at the time of publication. The `enforce_encrypted_bundle_trigger` / `check_encrypted_bundle_on_insert` content … Sep 26, 2026
CVE-2026-100620 LOW 3.8 Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the … Sep 26, 2026
CVE-2026-100619 HIGH 8.8 Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal … Sep 26, 2026
CVE-2026-100618 HIGH 8.5 Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, … Sep 26, 2026
CVE-2026-100617 HIGH 8.8 Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers … Sep 26, 2026
CVE-2026-100616 MEDIUM 5.5 capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table … Sep 26, 2026
CVE-2026-100615 HIGH 8.8 Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover … Sep 26, 2026