Known Vulnerabilities for Canvas by Codesupplyco
Listed below are 10 of the newest known vulnerabilities associated with "Canvas" by "Codesupplyco".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49386 json | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Pl... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-45644 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allow... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-45312 json | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in ... | Not Provided | 2026-05-29 | 2026-06-02 |
| CVE-2026-42046 json | libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas impo... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-40933 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serial... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-35656 json | OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trust... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-35643 json | OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbi... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-35634 json | OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest(... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2026-32814 json | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image wit... | Not Provided | 2026-05-19 | 2026-05-20 |
| CVE-2026-11136 json | Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a... | Not Provided | 2026-06-04 | 2026-06-05 |