Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-56314 | Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing … | High (7.1) | 2026-06-22 | Environment Specific |
| CVE-2026-56311 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC functio… | Medium (5.3) | 2026-06-22 | Environment Specific |
| CVE-2026-56306 | Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to byp… | Medium (6.4) | 2026-06-22 | Environment Specific |
| CVE-2026-56280 | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API… | High (7.1) | 2026-06-22 | Environment Specific |
| CVE-2026-56268 | Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint.… | High (7.7) | 2026-06-22 | Environment Specific |