#Patchstack
🟠 CVE-2026-100627 - High (8.1)

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization fla...

https://www.thehackerwire.com/vulnerability/CVE-2026-100627/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 7:17 AM
🟠 CVE-2026-100623 - High (8.8)

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase ...

https://www.thehackerwire.com/vulnerability/CVE-2026-100623/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 7:17 AM
🟠 CVE-2026-100622 - High (7.5)

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts f...

https://www.thehackerwire.com/vulnerability/CVE-2026-100622/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 7:17 AM
🔴 CVE-2026-101002 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the functi...

https://www.thehackerwire.com/vulnerability/CVE-2026-101002/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 7:01 AM
🔴 CVE-2026-101001 - Critical (10)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function e...

https://www.themasherwire.com/vulnerability/CVE-2026-101001/

#infosec #potatosecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 5:48 AM
🟠 CVE-2026-100908 - High (7.5)

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the co...

https://www.thehackerwire.com/vulnerability/CVE-2026-100908/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 5:32 AM
🔴 CVE-2026-101001 - Critical (10)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function e...

https://www.thehackerwire.com/vulnerability/CVE-2026-101001/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 5:31 AM
🔴 CVE-2026-101000 - Critical (10)

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function u...

https://www.thehackerwire.com/vulnerability/CVE-2026-101000/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 5:31 AM
🟠 CVE-2026-100631 - High (7.5)

Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9...

https://www.thehackerwire.com/vulnerability/CVE-2026-100631/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:46 AM
🟠 CVE-2026-100639 - High (8.8)

SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button marku...

https://www.thehackerwire.com/vulnerability/CVE-2026-100639/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:46 AM
🟠 CVE-2026-100638 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpo...

https://www.thehackerwire.com/vulnerability/CVE-2026-100638/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:46 AM
🟠 CVE-2026-100637 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint...

https://www.thehackerwire.com/vulnerability/CVE-2026-100637/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:31 AM
🟠 CVE-2026-81655 - High (7.5)

The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its ...

https://www.thehackerwire.com/vulnerability/CVE-2026-81655/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:31 AM
🟠 CVE-2026-86609 - High (8.8)

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted th...

https://www.themasherwire.com/vulnerability/CVE-2026-86609/

#infosec #potatosecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:31 AM
🟠 CVE-2026-86609 - High (8.8)

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted th...

https://www.thehackerwire.com/vulnerability/CVE-2026-86609/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:31 AM
🔴 CVE-2026-100896 - Critical (9.9)

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the fu...

https://www.thehackerwire.com/vulnerability/CVE-2026-100896/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:30 AM
🟠 CVE-2026-100636 - High (7.6)

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML end...

https://www.thehackerwire.com/vulnerability/CVE-2026-100636/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:16 AM
🟠 CVE-2026-100646 - High (8.1)

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8...

https://www.thehackerwire.com/vulnerability/CVE-2026-100646/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:16 AM
🟠 CVE-2026-100645 - High (8)

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery...

https://www.thehackerwire.com/vulnerability/CVE-2026-100645/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:16 AM
🟠 CVE-2026-100644 - High (7.5)

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the...

https://www.thehackerwire.com/vulnerability/CVE-2026-100644/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:01 AM
🟠 CVE-2026-100643 - High (8)

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textar...

https://www.thehackerwire.com/vulnerability/CVE-2026-100643/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:01 AM
🟠 CVE-2026-100642 - High (7.6)

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in t...

https://www.thehackerwire.com/vulnerability/CVE-2026-100642/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 2:01 AM
🟠 CVE-2026-100641 - High (8)

SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it ...

https://www.thehackerwire.com/vulnerability/CVE-2026-100641/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 1:46 AM
🟠 CVE-2026-100660 - High (7.5)

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains u...

https://www.thehackerwire.com/vulnerability/CVE-2026-100660/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 1:46 AM
🟠 CVE-2026-100657 - High (7.5)

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder....

https://www.thehackerwire.com/vulnerability/CVE-2026-100657/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 1:46 AM