Known Vulnerabilities for Apps by Deco-cx
Listed below are 10 of the newest known vulnerabilities associated with "Apps" by "Deco-cx".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84856 json | A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json o... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82642 json | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOM... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-82635 json | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads direc... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-82543 json | A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of th... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-82477 json | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network r... | Not Provided | 2026-08-29 | 2026-09-01 |
| CVE-2026-82240 json | Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82089 json | The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-81094 json | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for ... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-81035 json | Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the cal... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-78154 json | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its... | Not Provided | 2026-08-24 | 2026-08-25 |