Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49608
Total
4010
Critical
14727
High
14463
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48077 | MEDIUM | 5.3 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before … | Aug 06, 2026 |
| CVE-2026-48076 | MEDIUM | 6.5 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` … | Aug 06, 2026 |
| CVE-2026-48075 | MEDIUM | 6.5 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any … | Aug 06, 2026 |
| CVE-2026-48074 | LOW | 2.7 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying … | Aug 06, 2026 |
| CVE-2026-48071 | MEDIUM | 5.8 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. … | Aug 06, 2026 |
| CVE-2026-48054 | HIGH | 8.8 | OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test … | Aug 06, 2026 |
| CVE-2026-47765 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, … | Aug 06, 2026 |
| CVE-2026-47194 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing … | Aug 06, 2026 |
| CVE-2026-47185 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing … | Aug 06, 2026 |
| CVE-2026-45573 | MEDIUM | 6.4 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification … | Aug 06, 2026 |
| CVE-2026-45572 | MEDIUM | 4.8 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can … | Aug 06, 2026 |
| CVE-2026-45415 | MEDIUM | 6.0 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce … | Aug 06, 2026 |
| CVE-2026-45414 | HIGH | 8.5 | Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by … | Aug 06, 2026 |
| CVE-2026-45378 | HIGH | 7.5 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment … | Aug 06, 2026 |
| CVE-2026-43632 | HIGH | 8.1 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that … | Aug 06, 2026 |
| CVE-2026-43631 | HIGH | 8.1 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated … | Aug 06, 2026 |
| CVE-2026-43630 | MEDIUM | 6.5 | llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the … | Aug 06, 2026 |
| CVE-2026-43629 | HIGH | 8.1 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size … | Aug 06, 2026 |
| CVE-2026-43628 | HIGH | 7.8 | llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap … | Aug 06, 2026 |
| CVE-2026-43627 | HIGH | 7.8 | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when … | Aug 06, 2026 |
| CVE-2026-41861 | MEDIUM | 4.2 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path … | Aug 06, 2026 |
| CVE-2026-3418 | CRITICAL | 9.1 | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary … | Aug 06, 2026 |
| CVE-2026-3415 | HIGH | 8.7 | The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows … | Aug 06, 2026 |
| CVE-2026-33181 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a duplicate of CVE-2026-33942. Notes: All CVE users … | Aug 06, 2026 |
| CVE-2026-1289 | HIGH | 7.8 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a … | Aug 06, 2026 |