Cap-go / capgo.app
capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
- CWE
- CWE-200
- Published
- Sep 26, 2026
- Updated
- Sep 28, 2026
Live Threat Intelligence
Monitor, filter, and investigate recent new and updated vulnerability records.
Live monitoring active
Automatic refresh every ~30 seconds
Records loaded
100
New CVEs
22
Updated CVEs
78
Known Exploited
0
CISA ADP KEV only
Live feed
100 of 100 records
capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
Capgo bundle promotion API channel RBAC deny override bypass
Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection
Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if
SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie
Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)
SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL
Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
VxWorks 7 Memory Resource leak
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6
deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decision
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
DeepSeek deepseek-harness Bundle Patch profile.ts loadProfile path traversal
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8
Authenticated Command Injection in FreePBX UCP Interface
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module
Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer
Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of syntactic correctness of input
SiYuan before v3.8.4 Stored XSS via Attribute View textarea
vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt
vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass
Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection
grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass
FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module
ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference
Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes
OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
stoatchat before 0.15.5 Denial of Service via mass mentions
stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket
SailPoint IdentityIQ Improper Form Validation Vulnerability
Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
WatchGuard AP Authenticated Command Injection in Diagnostic CLI
WatchGuard AP Command Injection in Internal Management API Allows Command Execution
deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox
Improper Permission Assignment in Scheduler Service
Time-based SQL Injection in Dayforce Payroll
Multiple Reflected XSS in Dayforce Payroll
Path Traversal in Dayforce Payroll
Budibase before 3.45.0 SQL Injection via column-rename DDL
SQLi in Iron Mountain's enVision
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Bluehood: Missing authentication on Bluehood API routes when web auth is enabled
Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast
Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service
Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives
Hugo before 0.166.0 Stored XSS via lineAnchors code block option
Session Not Revoked Server-Side on Logout in Rancher
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
Axios: Header Injection via Inherited headers After Minimal Interceptor
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript
Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE
OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2
OpenClaw before 2026.8.1 Local File Read via Outbound Attachments
Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment
OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass
Axios: Prototype Pollution Gadget in axios toFormData Options
Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
OpenClaw before 2026.8.1 Exec Approval Directory Binding
FreePBX: Authenticated API generatedocs Host Command Injection
Cotonti through 1.0.0 Reflected XSS via message.php lng parameter
Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path
FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)
Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module
Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128
Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
Vulnerability in discord
@xhmikosr/decompress: Path traversal via symlink chain
OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass
OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade
Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)
OpenClaw before 2026.8.1 Authorization Bypass via sessions.create
OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname
Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal