Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-56701

Grav – XML External Entity Injection via SVG Upload_CVE-2026-56701

Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers ...

Grav Grav CVE
MEDIUM 6.3 CVE-2026-56376

ImageMagick – Heap Use-After-Free in Meta Coder_CVE-2026-56376

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written ...

ImageMagick ImageMagick CVE
HIGH 8.7 CVE-2026-56322

Capgo – Information Disclosure via Unauthenticated /updates defaultChannel Parameter_CVE-2026-56322

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel pa...

Capgo Capgo CVE
CRITICAL 9.3 CVE-2026-56315

picklescan – Remote Code Execution via Unblocked Standard Library Modules_CVE-2026-56315

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, a...

picklescan picklescan CVE
MEDIUM 6.8 CVE-2026-56301

Nuxt – Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux_CVE-2026-56301

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abs...

Nuxt Nuxt 4.0.0 CVE
MEDIUM 6 CVE-2026-56275

Flowise – Server-Side Request Forgery via Execute Flow Base URL_CVE-2026-56275

Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validat...

Flowise Flowise CVE
HIGH 8.7 CVE-2026-56274

Flowise – Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess_CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validat...

Flowise Flowise CVE
MEDIUM 5.3 CVE-2026-56263

Crawl4AI – Stored Cross-Site Scripting in Monitor Dashboard_CVE-2026-56263

Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via ...

Crawl4AI Crawl4AI CVE
CRITICAL 9.2 CVE-2026-56258

Crawl4AI – Arbitrary File Write via output_path Symlink and TOCTOU_CVE-2026-56258

Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to w...

Crawl4AI Crawl4AI 0.8.8 CVE
HIGH 8.7 CVE-2026-56248

Capgo – Unauthenticated Denial-of-Service via audit_logs RLS Policy_CVE-2026-56248

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-L...

Cap-go capgo CVE