Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2026-100642 — SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests wit…

siyuan | Remote | Cross-Site Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.6 HIGH
CVE-2026-100641 — SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a…

siyuan | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.6 HIGH
CVE-2026-100640 — SiYuan before v3.8.4 Clipboard Data Disclosure via IPC

SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboard…

siyuan | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100639 — SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from c…

siyuan | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100638 — SiYuan before v3.8.4 Path Traversal via setNotebookIcon

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outsi…

siyuan | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100637 — SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can sup…

siyuan | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100636 — SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside t…

siyuan | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.2 HIGH
CVE-2026-100635 — SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie

SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An …

siyuan | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100634 — SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows

SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender…

siyuan | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.5 HIGH
CVE-2026-100633 — SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations

SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is appl…

siyuan | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100632 — Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery

Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incomplet…

parse-server | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100631 — Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not v…

parse-server | Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100630 — AVideo Stored XSS via HTML Entity Bypass in trailer1 Field

AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can sto…

avideo | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.0 HIGH
CVE-2026-100629 — Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH

Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank do…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100628 — capgo.app before 12.128.12 Authentication Bypass via apikey

capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, l…

Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.1 HIGH
CVE-2026-100627 — Capgo bundle promotion API channel RBAC deny override bypass

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API k…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100626 — capgo through 12.128.2 IDOR via PUT /app icon endpoint

capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply a…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100625 — Capgo Build Upload Proxy Authorization Bypass via TUS Resource

Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_j…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100624 — Capgo.app before 12.264.5 Upload Expiry Bypass via build upload

Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, an upload_expires_at timestam…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100623 — Capgo Authentication Bypass via Direct PostgREST org_users Table Write

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14454 Results