Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-66838
  • Hex/postgrex
  • github.com/elixir-ecto/postgrex
SQL injection via the :comment option in Postgrex.stream/4 3 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-71555
  • github.com/thm-health/pilos
PILOS: Reverse tabnabbing in room description 18 hours ago
  • Fix available
  • Severity - 4.1 (Medium)
CVE-2026-48054
  • github.com/openzeppelin/contracts-wizard
OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri 18 hours ago
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-49391
  • github.com/frappe/frappe
Frappe: Stored XSS in Column Headers via Data Import 18 hours ago
  • Fix available
  • Severity - 5.1 (Medium)
CVE-2026-48088
  • github.com/open-reception/appointment-booking-software
OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 18 hours ago
  • Fix available
  • Severity - 9.4 (Critical)
CVE-2026-48087
  • github.com/open-reception/appointment-booking-software
OpenReception: WebAuthn passkey injection allows account takeover 18 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-70636
  • github.com/flowiseai/flowise
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint 18 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-67622
  • github.com/flowiseai/flowise
Flowise 3.1.4 IDOR in OpenAI Assistants Integration 18 hours ago
  • No fix available
  • Severity - 8.5 (High)
CVE-2026-67434
  • github.com/phpcsstandards/php_codesniffer
PHP_CodeSniffer gitblame report command injection via crafted filename 18 hours ago
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-67621
  • github.com/flowiseai/flowise
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints 18 hours ago
  • No fix available
  • Severity - 7.2 (High)
CVE-2026-48086
  • github.com/open-reception/appointment-booking-software
OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 18 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-48085
  • github.com/open-reception/appointment-booking-software
OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 18 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-71498
  • github.com/uhop/node-re2
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript 18 hours ago
  • Fix available
  • Severity - 5.1 (Medium)
CVE-2026-47765
  • github.com/frappe/frappe
Frappe: Lack of Permissions in restore/bulk_restore 18 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-71430
  • github.com/uhop/node-re2
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length 18 hours ago
  • Fix available
  • Severity - 6.2 (Medium)
CVE-2026-47194
  • github.com/frappe/frappe
Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain 18 hours ago
  • Fix available
  • Severity - 8.6 (High)