Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-56338

Capgo – Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint_CVE-2026-56338

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authe...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56337

Capgo – Information Disclosure via Unauthenticated RPC Function exist_app_v2_CVE-2026-56337

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attacker...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56310

Cap-go – Authorization Bypass in Organization Members Endpoint via API Key Scope Bypass_CVE-2026-56310

Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56302

Capgo – Unsecured Supabase Images Bucket via Missing Row Level Security_CVE-2026-56302

Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, inse...

Capgo Capgo CVE
MEDIUM 5.6 CVE-2026-56272

Flowise – Insufficient Password Salt Rounds in Bcrypt Hashing_CVE-2026-56272

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds...

Flowise Flowise CVE
MEDIUM 4.3 CVE-2026-56269

Flowise – Weak Default Token Hash Secret in JWT Token Encryption_CVE-2026-56269

Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET env...

Flowise Flowise CVE
MEDIUM 6.9 CVE-2026-56262

Crawl4AI – Unauthenticated Access to Monitor Endpoints via Docker API Server_CVE-2026-56262

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to acce...

Crawl4AI Crawl4AI CVE
MEDIUM 5.3 CVE-2026-13163

Lack of input validation in Mailerup input parameter leads to Open Redirect_CVE-2026-13163

Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c//) in Mailerup

Mailerup Mailerup CVE
MEDIUM 5.5 CVE-2026-11968

Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) in TortoiseGit_CVE-2026-11968

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

TortoiseGit team TortoiseGit 1.8.10.0 CVE
MEDIUM 6.9 CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via Host header_CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 ...

Pentestify Pentestify CVE