Known Vulnerabilities for Reference Application by Openmrs
Listed below are 4 of the newest known vulnerabilities associated with "Reference Application" by "Openmrs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104039 json | A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-103237 json | MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpo... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-94419 json | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the for... | Not Provided | 2026-09-27 | 2026-09-29 |
| CVE-2026-93758 json | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user ... | Not Provided | 2026-09-18 | 2026-09-21 |
| CVE-2026-93598 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script... | Not Provided | 2026-09-18 | 2026-09-22 |
| CVE-2026-91777 json | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pen... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-90198 json | In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix use-after-free in snd_card_do_free() A ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-88789 json | Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache C... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-86749 json | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::... | Not Provided | 2026-09-09 | 2026-09-19 |
| CVE-2026-86472 json | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 ... | Not Provided | 2026-09-15 | 2026-09-15 |