Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.70% | — | Openreception Appointment Booking SoftwareAI | 17/9/2026 | 30/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind… | |
| Aplazada | Crítica (9.4) | 0.38% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication.… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the… | |
| Aplazada | Crítica (9.9) | 0.44% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating… | |
| Aplazada | Crítica (9.8) | 0.59% | — | OpenreceptionAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an… | |
| Aplazada | Alta (7.4) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost… | |
| Aplazada | Media (6.5) | 0.36% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout… | |
| Aplazada | Baja (3.7) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.… | |
| Aplazada | Alta (8.1) | 0.24% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page… | |
| Aplazada | Alta (8) | 0.47% | — | Openreception Appointment Booking SoftwareAIPostgresqlAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live… | |
| Aplazada | Alta (7.4) | 0.50% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The… | |
| Aplazada | Media (5.3) | 0.34% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false`… | |
| Aplazada | Media (5.3) | 0.43% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any party who knows or obtains a valid… | |
| Aplazada | Media (6.5) | 0.33% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex zeroes), `bootstrap-verify` (validates the… | |
| Aplazada | Media (6.5) | 0.42% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash`… | |
| Aplazada | Baja (2.7) | 0.29% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table… | |
| Aplazada | Media (5.8) | 0.40% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's… |