|
1731
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_binding…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-56321
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1732
|
7.1 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted b…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-56314
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1733
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers c…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-56299
|
2026-06-24 00:16 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1734
|
8.6 |
HIGH
Network
|
-
|
-
|
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenti…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-56266
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1735
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticated users with org write permissions to create unlimited demo applications withou…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-56255
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1736
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key withou…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-56234
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1737
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely larg…
|
CWE-20
Improper Input Validation
|
CVE-2026-56228
|
2026-06-24 00:16 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1738
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body i…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-54288
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1739
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Window…
|
CWE-22
Path Traversal
|
CVE-2026-54286
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1740
|
- |
|
-
|
-
|
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chun…
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-54278
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|