Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-49005 | 2026-08-26 | N/A | 2.4 LOW | ||
| The root password hash of the device can be obtained through unencrypted information in the firmware. | |||||
| CVE-2026-49004 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access. | |||||
| CVE-2026-8029 | 2026-08-26 | N/A | 3.9 LOW | ||
| The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data. | |||||
| CVE-2026-76157 | 2026-08-26 | N/A | N/A | ||
| Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory. | |||||
| CVE-2026-49007 | 2026-08-26 | N/A | 7.5 HIGH | ||
| By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface. | |||||
| CVE-2026-49006 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission. | |||||
| CVE-2026-76155 | 2026-08-26 | N/A | N/A | ||
| Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials. | |||||
| CVE-2026-76158 | 2026-08-26 | N/A | N/A | ||
| External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences. | |||||
| CVE-2026-76156 | 2026-08-26 | N/A | N/A | ||
| OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root. | |||||
| CVE-2026-18597 | 2026-08-26 | N/A | 8.5 HIGH | ||
| The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure. | |||||
| CVE-2026-58434 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Private Repository Metadata Remains Accessible After Access Revocation | |||||
| CVE-2026-58417 | 2026-08-26 | N/A | 7.5 HIGH | ||
| REST API exposes organization membership of private organizations to public | |||||
| CVE-2026-59763 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | |||||
| CVE-2026-57886 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Cross-repository issue/comment attachment re-linking can expose private attachment content | |||||
| CVE-2026-55986 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| Email Management API Bypasses ManageCredentials Feature Restrictions | |||||
| CVE-2026-58440 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | |||||
| CVE-2026-58436 | 2026-08-26 | N/A | 7.5 HIGH | ||
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | |||||
| CVE-2026-42931 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | |||||
| CVE-2026-58443 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Public-only repository tokens can update private PR head branches | |||||
| CVE-2026-58427 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | |||||
