Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49608
Total
4010
Critical
14727
High
14463
Medium
CVE ID Severity Score Description Published
CVE-2026-64652 LOW 3.3 GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in … Aug 06, 2026
CVE-2026-63725 HIGH 7.2 sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar … Aug 06, 2026
CVE-2026-63637 HIGH 8.6 Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating … Aug 06, 2026
CVE-2026-62857 UNKNOWN Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and … Aug 06, 2026
CVE-2026-61632 MEDIUM 5.3 PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to … Aug 06, 2026
CVE-2026-5857 HIGH 8.1 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag … Aug 06, 2026
CVE-2026-5856 HIGH 7.1 Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop … Aug 06, 2026
CVE-2026-5855 HIGH 7.5 Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no … Aug 06, 2026
CVE-2026-5336 MEDIUM 6.8 The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to … Aug 06, 2026
CVE-2026-54717 MEDIUM 5.4 Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using … Aug 06, 2026
CVE-2026-53984 CRITICAL 9.1 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer … Aug 06, 2026
CVE-2026-53983 HIGH 8.6 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to … Aug 06, 2026
CVE-2026-50159 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to … Aug 06, 2026
CVE-2026-49391 UNKNOWN Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, … Aug 06, 2026
CVE-2026-48088 CRITICAL 9.4 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public … Aug 06, 2026
CVE-2026-48087 CRITICAL 9.8 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between … Aug 06, 2026
CVE-2026-48086 CRITICAL 9.9 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single … Aug 06, 2026
CVE-2026-48085 CRITICAL 9.8 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to … Aug 06, 2026
CVE-2026-48084 HIGH 7.4 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit … Aug 06, 2026
CVE-2026-48083 MEDIUM 6.5 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema … Aug 06, 2026
CVE-2026-48082 LOW 3.7 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work … Aug 06, 2026
CVE-2026-48081 HIGH 8.1 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` … Aug 06, 2026
CVE-2026-48080 HIGH 8.0 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to … Aug 06, 2026
CVE-2026-48079 HIGH 7.4 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's … Aug 06, 2026
CVE-2026-48078 MEDIUM 5.3 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a … Aug 06, 2026