Filter and search through 392,315 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-24429 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication a... | 0.0 | 0 | Neutral | No |
| No |
| CVE-2026-24428 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a ... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24423 | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. T... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24422 | ### Summary Several public API endpoints return email addresses and non‑public records (e.g. open questions with isVisible=false). ### Details OpenQu... | 5.3 | 196 | Neutral | No | No |
| CVE-2026-24421 | ### Summary Authenticated non‑admin users can call /api/setup/backup and trigger a configuration backup. The endpoint only checks authentication, not ... | 6.5 | 260 | Neutral | No | No |
| CVE-2026-24420 | ### Summary A logged‑in user without the dlattachment right can download FAQ attachments. This is due to a permissive permission check in attachment.p... | 6.5 | 260 | Neutral | No | No |
| CVE-2026-24412 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aH... | 8.8 | 553 | Neutral | No | No |
| CVE-2026-24411 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Un... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24410 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Un... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24409 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Un... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24408 | ### Summary The sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. ### Details `_OAuthSession` creates a uniqu... | 0.0 | 158 | Neutral | No | Yes |
| CVE-2026-24407 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Un... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24406 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a ... | 8.8 | 553 | Neutral | No | No |
| CVE-2026-24405 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a ... | 8.8 | 553 | Neutral | No | No |
| CVE-2026-24404 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIc... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24403 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an ... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-24402 | Rejected reason: GitHub cannot issue a CVE for this Security Advisory because this advisory includes information about more than one vulnerability. ... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24401 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemo... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-24400 | An XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)` method initiali... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24399 | ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads ... | 9.3 | 577 | Neutral | No | No |