Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56232

Capgo – Subkey Scope Bypass in middlewareKey via x-limited-key-id Header_CVE-2026-56232

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewar...

Capgo Capgo CVE
HIGH 7.2 CVE-2026-56231

Capgo – Broken Object Level Authorization in Build Job Control via jobId Parameter_CVE-2026-56231

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:job...

Capgo Capgo CVE
CRITICAL 9.3 CVE-2026-56223

Capgo – Account Takeover via Cross-Domain SSO Email Assertion in provision-user_CVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbi...

Capgo Capgo CVE
LOW 1.1 CVE-2026-13140

Stored Cross-Site Scripting in Canarytokens.org_CVE-2026-13140

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledg...

Thinkst Applied Research Canarytokens sha-4116b92cb CVE
HIGH 7.6 CVE-2025-71354

picklescan – Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText_CVE-2025-71354

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. At...

picklescan picklescan CVE
HIGH 8.5 CVE-2025-71332

Flowise – SQL Injection in importChatflows API via chatflow.id Parameter_CVE-2025-71332

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, a...

Flowise Flowise CVE
MEDIUM 5.3 CVE-2026-13163

Lack of input validation in Mailerup input parameter leads to Open Redirect_CVE-2026-13163

Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c//) in Mailerup

Mailerup Mailerup CVE
HIGH 8.8 CVE-2026-12242

AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute_CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' ...

adegans AdRotate Banner Manager CVE
HIGH 8.4 CVE-2026-42450

OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser_CVE-2026-42450

OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with ...

AcademySoftwareFoundation OpenColorIO < 2.5.2 CVE
HIGH 8.6 CVE-2026-35025

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR_CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory AC...

ProFTPD Project ProFTPD 1.3.9b, 1.3.10rc2 CVE