Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,247
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 801 - 820 of 35,663 CVEs
CVE-2026-56213 MEDIUM - 5.3

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for any app_id. Attackers can exploit this by calling the RPC endp...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to verify the initiator'...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-11551 CRITICAL - 9.8

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to ...

Vendor: wpmudev
Product: Branda โ€“ White Label & Branding, Free Login Page Customizer
Published: Jun 20, 2026
Source: NVD
CVE-2026-56082 HIGH - 7.5

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated att...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56081 CRITICAL - 9.1

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account cl...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56080 MEDIUM - 4.9

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat the account as non-c...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56079 MEDIUM - 6.5

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing s...

Vendor: Capgo
Product: Capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56073 CRITICAL - 9.4

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabli...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-55878 HIGH - 7.8

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

Vendor: composer
Product: symfony/ux-toolkit
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55877 MEDIUM - 6.1

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

Vendor: composer
Product: symfony/ux-icons
Published: Jun 19, 2026
Source: GitHub

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

Vendor: go
Product: github.com/authzed/spicedb
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55776 MEDIUM - 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao's System Backend allows Unauthorized Management of the containing Namespace

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} โ€” incomplete fix of CVE-2026-45808

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55770 MEDIUM - 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55692 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55650 MEDIUM - 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Vendor: npm
Product: @outerbase/studio
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55447 CRITICAL - 9.6

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the ...

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55446 HIGH - 7.5

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinit...

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-50559 HIGH - 7.5

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, ...

Vendor: quarkusio
Product: quarkus
Published: Jun 19, 2026
Source: NVD