Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64652 | LOW | 3.3 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in … | Aug 06, 2026 |
| CVE-2026-63725 | HIGH | 7.2 | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar … | Aug 06, 2026 |
| CVE-2026-63637 | HIGH | 8.6 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating … | Aug 06, 2026 |
| CVE-2026-62857 | UNKNOWN | — | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and … | Aug 06, 2026 |
| CVE-2026-61632 | MEDIUM | 5.3 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to … | Aug 06, 2026 |
| CVE-2026-5857 | HIGH | 8.1 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag … | Aug 06, 2026 |
| CVE-2026-5856 | HIGH | 7.1 | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop … | Aug 06, 2026 |
| CVE-2026-5855 | HIGH | 7.5 | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no … | Aug 06, 2026 |
| CVE-2026-5336 | MEDIUM | 6.8 | The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to … | Aug 06, 2026 |
| CVE-2026-54717 | MEDIUM | 5.4 | Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using … | Aug 06, 2026 |
| CVE-2026-53984 | CRITICAL | 9.1 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer … | Aug 06, 2026 |
| CVE-2026-53983 | HIGH | 8.6 | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to … | Aug 06, 2026 |
| CVE-2026-50159 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to … | Aug 06, 2026 |
| CVE-2026-49391 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, … | Aug 06, 2026 |
| CVE-2026-48088 | CRITICAL | 9.4 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public … | Aug 06, 2026 |
| CVE-2026-48087 | CRITICAL | 9.8 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between … | Aug 06, 2026 |
| CVE-2026-48086 | CRITICAL | 9.9 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single … | Aug 06, 2026 |
| CVE-2026-48085 | CRITICAL | 9.8 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to … | Aug 06, 2026 |
| CVE-2026-48084 | HIGH | 7.4 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit … | Aug 06, 2026 |
| CVE-2026-48083 | MEDIUM | 6.5 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema … | Aug 06, 2026 |
| CVE-2026-48082 | LOW | 3.7 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work … | Aug 06, 2026 |
| CVE-2026-48081 | HIGH | 8.1 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` … | Aug 06, 2026 |
| CVE-2026-48080 | HIGH | 8.0 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to … | Aug 06, 2026 |
| CVE-2026-48079 | HIGH | 7.4 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's … | Aug 06, 2026 |
| CVE-2026-48078 | MEDIUM | 5.3 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a … | Aug 06, 2026 |