Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-56784

OpenRemote Manager – Cross-Tenant IDOR in Bulk Alarm Deletion_CVE-2026-56784

OpenRemote Manager before 1.24.2 contains an insecure direct object reference vulnerability in the removeAlarms() method that allows authenticated ...

openremote openremote CVE
HIGH 7.1 CVE-2026-56701

Grav – XML External Entity Injection via SVG Upload_CVE-2026-56701

Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers ...

Grav Grav CVE
HIGH 8.7 CVE-2026-56322

Capgo – Information Disclosure via Unauthenticated /updates defaultChannel Parameter_CVE-2026-56322

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel pa...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56274

Flowise – Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess_CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validat...

Flowise Flowise CVE
HIGH 8.7 CVE-2026-56248

Capgo – Unauthenticated Denial-of-Service via audit_logs RLS Policy_CVE-2026-56248

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-L...

Cap-go capgo CVE
HIGH 8.6 CVE-2026-56243

Capgo – Hashed API Key Enforcement Bypass via PostgREST/RLS Plane_CVE-2026-56243

Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56225

Capgo – Authorization Bypass in API Key Management via App-Limited Keys_CVE-2026-56225

Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys crea...

Capgo Capgo CVE
HIGH 8.6 CVE-2026-56222

Capgo – Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings_CVE-2026-56222

Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during ap...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-54892

Plug: quadratic-time decoding of nested query/body parameters enables denial of service_CVE-2026-54892

Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Co...

elixir-plug plug 1.15.0 CVE
HIGH 8.8 CVE-2026-10711

RCE in Akınsoft’s CafePlus_CVE-2026-10711

Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessin...

AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus 12.05.03 CVE