Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.37% | — | CapgoAISupabaseAISupabase PostgrestAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 15/7/2026 | 15/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when… | |
| Aplazada | Alta (8.7) | 0.56% | — | CapgoAISupabase PostgrestAI | 12/7/2026 | 13/7/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR,… | |
| Aplazada | Alta (7.1) | 0.43% | — | CapgoAIPostgrestAI | 10/7/2026 | 10/7/2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such… | |
| Aplazada | Media (6.9) | 0.36% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only the public sb_publishable_* key. An unauthenticated attacker can probe organization existence and leak sensitive… | |
| Aplazada | Alta (8.7) | 0.43% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated access. Because the function accepts a caller-supplied user UUID without verifying it matches the authenticated user, an… | |
| Aplazada | Alta (8.7) | 0.49% | — | Capgo BackendAISupabase PostgrestAIPostgresqlAI | 23/6/2026 | 23/6/2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries… | |
| Aplazada | Alta (8.6) | 0.39% | — | CapgoAIPostgrestAI | 23/6/2026 | 23/6/2026 | Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS… | |
| Aplazada | Media (6.9) | 0.39% | — | Supabase PostgrestAICapgoAI | 20/6/2026 | 24/6/2026 | Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauthenticated attacker using only the public Supabase API key… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 20/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpoints to determine… | |
| Aplazada | Alta (8.7) | 0.37% | — | CapgoAISupabaseAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert… | |
| Aplazada | Alta (7.1) | 0.41% | — | CapgoAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing secrets and delivery… |