Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-48087 — OpenReception: WebAuthn passkey injection allows account takeover

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` vali…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.9 CRITICAL
CVE-2026-48086 — OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN th…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.8 CRITICAL
CVE-2026-48085 — OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated …

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.4 HIGH
CVE-2026-48084 — OpenReception doesn't rate limit passphrase login attempts

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can su…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48083 — OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injectio…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, appl…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.7 LOW
CVE-2026-48082 — OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which …

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments…

Remote | Misconfiguration
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.1 HIGH
CVE-2026-48081 — OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rende…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` c…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.0 HIGH
CVE-2026-48080 — OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, super…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record…

Remote | Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.4 HIGH
CVE-2026-48079 — OpenReception's logout page clears local access_token before server-side revocation, leav…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-48078 — OpenReception's schedule endpoint discloses isPublic=false channels and slot availability…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns e…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-48077 — OpenReception: GET appointment by ID returns full appointment record without authorization

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}`…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48076 — OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false c…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48075 — OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment inje…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any c…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.7 LOW
CVE-2026-48074 — OpenReception: Staff deletion removes pending invites cross-tenant by email match

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying …

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.8 MEDIUM
CVE-2026-48071 — OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. T…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.8 HIGH
CVE-2026-48054 — OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests v…

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.1 HIGH
CVE-2026-47765 — Frappe: Lack of Permissions in restore/bulk_restore

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authentica…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.6 HIGH
CVE-2026-47194 — Frappe: Host header poisoning can redirect magic login links to an attacker-controlled do…

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker t…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.1 MEDIUM
CVE-2026-47185 — Frappe Has Broken Access Control in its Workspace Save API

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership,…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-45573 — Decidim: Push subscriptions can be abused for server-side requests

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow sto…

decidim | Remote | Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 10117 Results