2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-71324 — Traefik Traefik: Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71324

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream answers the CONNECT with a keep-alive non-2xx response and does not drain the body, Traefik returns the desynchronized backend socket to its shared pool and reuses it for other clients. An unauthentic CVSSv3.1 9.1 (CRITICAL) · EPSS 44th percentile

CWECWE 444VNDTraefikTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH

CVE-2026-70634 — TimescaleDB: through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70634

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a re CVSSv3.1 8.1 (HIGH)

CWECWE 125CWECWE 129VNDTimescaledbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-70558 — POST: Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded in source and shipped to every deployment. Anyone who can reach Dinky's HTTP port CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDPostTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-67689 — SQL: Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-67688 — ICS: This allows a remote attacker to execute arbitrary code.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDIcsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH

CVE-2026-67687 — Permissions: Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67687

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-67622 — Flowise: through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67622

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDFlowiseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 22:18Z
CRIT

CVE-2026-65400 — Apple Macos: An authentication issue was addressed with improved state management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65400

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile

CWECWE 287VNDAppleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH

CVE-2026-64665 — Statamic: Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64665

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such CVSSv3.1 8.1 (HIGH)

CWECWE 287CWECWE 290VNDStatamicTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH

CVE-2026-63637 — Dgraph: Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63637

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8. CVSSv3.1 8.6 (HIGH)

CWECWE 943VNDDgraphTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH

CVE-2026-5857 — Contiki: Impact ranges from information disclosure and denial of service to remote code execution on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5857

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDContikiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-53984 — Ground: Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53984

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDGroundTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-53983 — Ground: Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53983

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-chosen destinations. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then submit a data_submission eve CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDGroundTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-48088 — The handler logs an "Unauthorized crypto key storage attempt" warning when neither a session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48088

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. The handler logs an "Unauthorized crypto key storage attempt" warning when neither a session nor a registration cookie is present, then proceeds to insert the row CVSSv3.1 9.4 (CRITICAL)

CWECWE 862TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-48087 — Staff-list endpoints return user IDs to authenticated tenant members per the route signature; live

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the `userId` in the URL belongs to that email. An unauthenticated attacker requests a challenge for their own email, generates a registration response with their own CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-48086 — On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization de CVSSv3.1 9.9 (CRITICAL)

CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-48085 — This is distinct from the deployment race condition already documented on the `Claiming an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an admin already exists. Any unauthenticated network attacker who can submit a same-origin form POST gains full platform-level administrative control. The newly creat CVSSv3.1 9.8 (CRITICAL)

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-48081 — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48081

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page via `/api/public`, hydrated into the SvelteKit Button component, and rendered as `<a href="javascript:...">` elements without URL-scheme filtering. A patient who c CVSSv3.1 8.1 (HIGH)

CWECWE 79TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-48080 — Operators who configure a non-superuser PostgreSQL user via `secrets/postgres_user.txt` would expose a less privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48080

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live PostgreSQL connection string the application uses to connect to that tenant's database. In the tested official `docker-compose.prod.yml` deployment, the connection CVSSv3.1 8.0 (HIGH)

CWECWE 200TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-48054 — OpenZeppelin: Contracts Wizardis a web application to interactively build a contract out of components

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48054

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string literals at `zip-hardhat.ts:48` and `:50` without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as `https[:]//wizard CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDOpenzeppelinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-45414 — Decidim: Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45414

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2. CVSSv3.1 8.5 (HIGH)

CWECWE 639CWECWE 863VNDDecidimTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-43632 — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43632

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main thread destroys and frees vocab after the synchronization lock is released but bef CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 367TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-43631 — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43631

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while the server transitions to sleep mode, causing concurrent worker threads to dereference a freed vocab pointer that can be reclaimed with attacker-con CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 362TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH

CVE-2026-43629 — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43629

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state files where cell_count multiplication overflows or exceeds tensor buffer allocation to write attacker-controlled bytes past buffer boundaries, potenti CVSSv3.1 8.1 (HIGH)

CWECWE 787CWECWE 190TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT

CVE-2026-3418 — System: Successful exploitation permits an authenticated publisher to upload files to server-accessible locations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could l CVSSv3.1 9.1 (CRITICAL)

CWECWE 434TYPVulnerability
9.1
CVSS v3.1
96
Edit Score