Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49358
Total
3967
Critical
14633
High
14397
Medium
CVE ID Severity Score Description Published
CVE-2026-48077 MEDIUM 5.3 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before … Aug 06, 2026
CVE-2026-48076 MEDIUM 6.5 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` … Aug 06, 2026
CVE-2026-48075 MEDIUM 6.5 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any … Aug 06, 2026
CVE-2026-48074 LOW 2.7 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying … Aug 06, 2026
CVE-2026-48071 MEDIUM 5.8 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. … Aug 06, 2026
CVE-2026-48054 HIGH 8.8 OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test … Aug 06, 2026
CVE-2026-47765 UNKNOWN Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, … Aug 06, 2026
CVE-2026-47194 UNKNOWN Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing … Aug 06, 2026
CVE-2026-47185 UNKNOWN Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing … Aug 06, 2026
CVE-2026-45573 MEDIUM 6.4 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification … Aug 06, 2026
CVE-2026-45572 MEDIUM 4.8 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can … Aug 06, 2026
CVE-2026-45415 MEDIUM 6.0 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce … Aug 06, 2026
CVE-2026-45414 HIGH 8.5 Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by … Aug 06, 2026
CVE-2026-45378 HIGH 7.5 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment … Aug 06, 2026
CVE-2026-43632 HIGH 8.1 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that … Aug 06, 2026
CVE-2026-43631 HIGH 8.1 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated … Aug 06, 2026
CVE-2026-43630 MEDIUM 6.5 llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the … Aug 06, 2026
CVE-2026-43629 HIGH 8.1 llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size … Aug 06, 2026
CVE-2026-43628 HIGH 7.8 llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap … Aug 06, 2026
CVE-2026-43627 HIGH 7.8 llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when … Aug 06, 2026
CVE-2026-41861 MEDIUM 4.2 Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path … Aug 06, 2026
CVE-2026-3418 CRITICAL 9.1 The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary … Aug 06, 2026
CVE-2026-3415 HIGH 8.7 The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows … Aug 06, 2026
CVE-2026-33181 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a duplicate of CVE-2026-33942. Notes: All CVE users … Aug 06, 2026
CVE-2026-1289 HIGH 7.8 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a … Aug 06, 2026