Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-49005 2026-08-26 N/A 2.4 LOW
The root password hash of the device can be obtained through unencrypted information in the firmware.
CVE-2026-49004 2026-08-26 N/A 6.5 MEDIUM
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
CVE-2026-8029 2026-08-26 N/A 3.9 LOW
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.
CVE-2026-76157 2026-08-26 N/A N/A
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.
CVE-2026-49007 2026-08-26 N/A 7.5 HIGH
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
CVE-2026-49006 2026-08-26 N/A 5.3 MEDIUM
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CVE-2026-76155 2026-08-26 N/A N/A
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
CVE-2026-76158 2026-08-26 N/A N/A
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
CVE-2026-76156 2026-08-26 N/A N/A
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
CVE-2026-18597 2026-08-26 N/A 8.5 HIGH
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
CVE-2026-58434 2026-08-26 N/A 7.5 HIGH
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58417 2026-08-26 N/A 7.5 HIGH
REST API exposes organization membership of private organizations to public
CVE-2026-59763 2026-08-26 N/A 4.3 MEDIUM
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-57886 2026-08-26 N/A 5.9 MEDIUM
Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-55986 2026-08-26 N/A 5.4 MEDIUM
Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-58440 2026-08-26 N/A 6.8 MEDIUM
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58436 2026-08-26 N/A 7.5 HIGH
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-42931 2026-08-26 N/A 6.5 MEDIUM
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-58443 2026-08-26 N/A 9.1 CRITICAL
Public-only repository tokens can update private PR head branches
CVE-2026-58427 2026-08-26 N/A 7.5 HIGH
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145