Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56270

Flowise – Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint_CVE-2026-56270

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows ...

Flowise Flowise CVE
HIGH 7.1 CVE-2026-56257

Capgo – Authorization Bypass in App Ownership Transfer via Direct PostgREST Update_CVE-2026-56257

Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-b...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56256

Capgo – Two-Factor Authentication Bypass via Organization Management API_CVE-2026-56256

Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g...

Capgo Capgo CVE
HIGH 8.8 CVE-2026-56245

Supabase Capgo – Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPC_CVE-2026-56245

Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows un...

Cap-go capgo CVE
HIGH 7.1 CVE-2026-56244

Capgo – Webhook Signing Secret Disclosure via Non-Admin API Key_CVE-2026-56244

Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies o...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56232

Capgo – Subkey Scope Bypass in middlewareKey via x-limited-key-id Header_CVE-2026-56232

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewar...

Capgo Capgo CVE
HIGH 7.2 CVE-2026-56231

Capgo – Broken Object Level Authorization in Build Job Control via jobId Parameter_CVE-2026-56231

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:job...

Capgo Capgo CVE
HIGH 10 671F5C5A-5DF1-

Exploit for Improper Authentication in Dahuasecurity Ipc-Hum7Xxx_Firmware_671F5C5A-5DF1-5396-BCA3-038841185E26

Mô phỏng khai thác Dahua Authentication Bypass PoC CVE-2021-33044 Tổng quan Camera IP Dahua là thiết bị IoT được sử dụng phổ biến trong các hệ thốn...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 1C4C9845-A374-

Exploit for Improper Privilege Management in Enlightenment_1C4C9845-A374-55A0-891B-94D916CABECA

CVE-2022-37706 Overview CVE-2022-37706 adalah kerentanan Local Privilege Escalation LPE yang ditemukan pada komponen enlightenmentsys di lingkungan...

N/A N/A GITHUBEXPLOIT
HIGH 7.6 CVE-2025-71354

picklescan – Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText_CVE-2025-71354

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. At...

picklescan picklescan CVE