Filter and search through 392,598 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-21491 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) col... | 7.1 | 305 | Neutral | No |
| Yes |
| CVE-2026-21490 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) col... | 7.1 | 305 | Neutral | No | Yes |
| CVE-2026-21489 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and In... | 7.1 | 305 | Neutral | No | Yes |
| CVE-2026-21488 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bound... | 7.1 | 305 | Neutral | No | Yes |
| CVE-2026-21487 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, Us... | 7.1 | 305 | Neutral | No | Yes |
| CVE-2026-21486 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-b... | 7.8 | 431 | Neutral | No | Yes |
| CVE-2026-21485 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Be... | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-21484 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab560... | 5.3 | 132 | Neutral | No | No |
| CVE-2026-21483 | ## Security Advisory: Stored XSS Leading to Admin Account Takeover **Affected Versions:** ≤ 5.1.0 **Vulnerability Type:** CWE-79: Stored Cross-Site... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-21452 | ### Summary Affected Components: ``` org.msgpack.core.MessageUnpacker.readPayload() org.msgpack.core.MessageUnpacker.unpackValue() org.msgpack.value.E... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-21451 | ### Summary A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto 2.3.8 within the CMS page editor. Although the platform normally attem... | 8.4 | 710 | Neutral | Yes | Yes |
| CVE-2026-21450 | ### Summary SSTI is possible in Bagisto via type parameter can lead to RCE and other exploitations. ### Details 1. Go to `http://127.0.0.1:8000/admin... | 9.8 | 690 | Neutral | Yes | Yes |
| CVE-2026-21449 | ### Summary SSTI is possible via first name and last name parameters provided by lowest-privileged users. ### Details 1. Go to `http://127.0.0.1:8000/... | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-21448 | ### Summary SSTI when normal customer orders any product in add address step can inject value run in admin view. ### Details `As normal user` 1. Go to... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2026-21447 | ### Summary An Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items f... | 7.1 | 348 | Neutral | No | Yes |
| CVE-2026-21446 | ### Vulnerable Code **File:** `packages/Ibkul/Installer/src/Routes/Ib.php` ``` <?php use Illuminate\\Session\\Middleware\\StartSession; use Illum... | 9.8 | 717 | Neutral | No | Yes |
| CVE-2026-21445 | ### Summary Multiple critical API endpoints in Langflow are missing authentication controls, allowing any unauthenticated user to access sensitive use... | 9.1 | 798 | Neutral | Yes | Yes |
| CVE-2026-21444 | libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integrat... | 5.5 | 125 | Neutral | No | Yes |
| CVE-2026-21441 | ### Impact urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.6.2/advanced-usage.html#streaming-and-i-o) is designed for the efficient han... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-21440 | ### Summary **Description** A Path Traversal (CWE-22) vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrar... | 0.0 | 0 | Low | Yes | Yes |