Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-53984 — Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection …

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unaut…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.6 HIGH
CVE-2026-53983 — Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forger…

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to …

Remote | Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-50159 — Mermaid allows CSS injection applying to sibling elements of the diagram

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator sele…

mermaid | Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.1 MEDIUM
CVE-2026-49391 — Frappe: Stored XSS in Column Headers via Data Import

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated i…

frappe | Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.4 CRITICAL
CVE-2026-48088 — OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipi…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` acc…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.8 CRITICAL
CVE-2026-48087 — OpenReception: WebAuthn passkey injection allows account takeover

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` vali…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.9 CRITICAL
CVE-2026-48086 — OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN th…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.8 CRITICAL
CVE-2026-48085 — OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated …

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.4 HIGH
CVE-2026-48084 — OpenReception doesn't rate limit passphrase login attempts

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can su…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48083 — OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injectio…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, appl…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.7 LOW
CVE-2026-48082 — OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which …

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments…

Remote | Misconfiguration
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.1 HIGH
CVE-2026-48081 — OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rende…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` c…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.0 HIGH
CVE-2026-48080 — OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, super…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record…

Remote | Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.4 HIGH
CVE-2026-48079 — OpenReception's logout page clears local access_token before server-side revocation, leav…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-48078 — OpenReception's schedule endpoint discloses isPublic=false channels and slot availability…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns e…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-48077 — OpenReception: GET appointment by ID returns full appointment record without authorization

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}`…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48076 — OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false c…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-48075 — OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment inje…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any c…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.7 LOW
CVE-2026-48074 — OpenReception: Staff deletion removes pending invites cross-tenant by email match

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying …

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.8 MEDIUM
CVE-2026-48071 — OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-…

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. T…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 10116 Results