2026 CVE Vulnerabilities

48,535 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48085CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48084HIGH7.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri...
CVE-2026-48083MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48082LOW3.7OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48081HIGH8.1OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48080HIGH8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48079HIGH7.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48078MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48077MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48076MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie...
CVE-2026-48075MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48074LOW2.7OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48071MEDIUM5.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48054HIGH8.8OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin ...
CVE-2026-47765HIGH7.1Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints ...
CVE-2026-47194HIGH8.6Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation c...
CVE-2026-47185MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac...
CVE-2026-45573MEDIUM6.4Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45572MEDIUM4.8Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45415MEDIUM6Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45414HIGH8.5Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth...
CVE-2026-45378HIGH7.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-43632CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to...
CVE-2026-43631CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se...
CVE-2026-43630MEDIUM6.5llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now