NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1,... 2026-08-06 8.8 NETWORK HIGH NVD
CVE-2026-61632 PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vuln... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-5857 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte ... 2026-08-06 8.1 NETWORK HIGH NVD
CVE-2026-5856 Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the cal... 2026-08-06 7.1 ADJACENT_NETWORK HIGH NVD
CVE-2026-5855 Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-5336 The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the... 2026-08-06 6.8 NETWORK MEDIUM NVD
CVE-2026-54717 Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when ... 2026-08-06 5.4 NETWORK MEDIUM NVD
CVE-2026-53984 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's da... 2026-08-06 9.1 NETWORK CRITICAL NVD
CVE-2026-53983 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path tha... 2026-08-06 8.6 NETWORK HIGH NVD
CVE-2026-50159 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulner... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-49391 Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering ... 2026-08-06 5.1 NETWORK MEDIUM NVD
CVE-2026-48088 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /a... 2026-08-06 9.4 NETWORK CRITICAL NVD
CVE-2026-48087 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration h... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-48086 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pro... 2026-08-06 9.9 NETWORK CRITICAL NVD
CVE-2026-48085 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisione... 2026-08-06 9.8 NETWORK CRITICAL NVD