Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-56319

Capgo – App Existence Oracle via GET /statistics/app/:app_id_CVE-2026-56319

Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56307

Cap-go – Broken Cursor Pagination in /private/devices Endpoint_CVE-2026-56307

Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allo...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56304

picklescan – Arbitrary File Creation via logging.FileHandler Deserialization_CVE-2026-56304

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte fi...

picklescan picklescan CVE
MEDIUM 5.3 CVE-2026-56295

Capgo – Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys_CVE-2026-56295

Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass th...

Capgo Capgo CVE
MEDIUM 4.3 CVE-2026-56294

capacitor-native-biometric – Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceeded_CVE-2026-56294

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to va...

capacitor-native-biometric capacitor-native-biometric CVE
MEDIUM 6.9 CVE-2026-56282

Capgo – Information Disclosure via Unauthenticated /replication Endpoint_CVE-2026-56282

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQ...

Capgo Capgo CVE
MEDIUM 6 CVE-2026-56276

Flowise – Mass Assignment in PUT /api/v1/user Allows Password Hash Override_CVE-2026-56276

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify t...

Flowise Flowise CVE
MEDIUM 6.9 CVE-2026-56267

Flowise – PII Disclosure via Unauthenticated Forgot Password Endpoint_CVE-2026-56267

Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user ob...

Flowise Flowise CVE
MEDIUM 6.9 CVE-2026-56235

Capgo – Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions_CVE-2026-56235

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56228

Capgo – Denial of Service via Improper Password Policy Length Validation_CVE-2026-56228

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated ...

Capgo Capgo CVE