Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56443 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-56443)
vulnerability in code.gitea.io/gitea (CVE-2026-56443). Data can be tampered with by attackers. Exploitable via `PATCH /api/v1/admin/users/limuser`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-47667 |
|
Vulnerability in c (CVE-2026-47667)
vulnerability in c (CVE-2026-47667). Risk of unauthorized operations or information disclosure. Exploitable via ``fread``.
|
| CVE-2026-58439 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58439)
vulnerability in code.gitea.io/gitea (CVE-2026-58439). Data can be tampered with by attackers. Exploitable via ``official``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58440 |
|
Vulnerability in gitea.dev (CVE-2026-58440)
vulnerability in gitea.dev (CVE-2026-58440). Confidential information can be exposed externally. Exploitable via `GET /api/v1/repos/admin/wh-repo`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-15957 |
|
Vulnerability in Amazon aws (CVE-2026-15957)
vulnerability in Amazon aws (CVE-2026-15957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73650 |
|
Cross-Site Scripting (XSS) in svgo (CVE-2026-73650)
cross-site scripting in svgo (CVE-2026-73650). Confidential information can be exposed externally. Exploitable via ``script``. Mitigation: upgrade to `4.0.2` or later.
|
| CVE-2026-73653 |
|
Path Traversal in @vitest/browser (CVE-2026-73653)
path traversal in @vitest/browser (CVE-2026-73653). Confidential information can be exposed externally. Exploitable via ``allowWrite``. Mitigation: upgrade to `5.0.0-beta.6` or later.
|
| CVE-2026-57894 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-57894)
SSRF in code.gitea.io/gitea (CVE-2026-57894). Confidential information can be exposed externally. Exploitable via `POST /repo/migrate`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-55082 |
|
SQL Injection in CVE-2026-55082 (CVE-2026-55082)
SQL injection in CVE-2026-55082 (CVE-2026-55082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55084 |
|
SQL Injection in sqli (CVE-2026-55084)
SQL injection in sqli (CVE-2026-55084). Successful exploitation can lead to full system takeover. Exploitable via ``filter``.
|
| CVE-2026-55081 |
|
Cross-Site Scripting (XSS) in CVE-2026-55081 (CVE-2026-55081)
cross-site scripting in CVE-2026-55081 (CVE-2026-55081). Risk of unauthorized operations or information disclosure. Exploitable via ``scope``. Mitigation: upgrade to `2.42.5.1` or later.
|
| CVE-2026-56577 |
|
Vulnerability in hcltech (CVE-2026-56577)
vulnerability in hcltech (CVE-2026-56577). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56578 |
|
Information Disclosure in hcltech (CVE-2026-56578)
vulnerability in hcltech (CVE-2026-56578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56579 |
|
Information Disclosure in hcltech (CVE-2026-56579)
vulnerability in hcltech (CVE-2026-56579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21579 |
|
Information Disclosure in atlassian (CVE-2026-21579)
vulnerability in atlassian (CVE-2026-21579). Confidential information can be exposed externally.
|
| CVE-2026-44880 |
|
Vulnerability in hpe (CVE-2026-44880)
vulnerability in hpe (CVE-2026-44880). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16439 |
|
Vulnerability in eclipse (CVE-2026-16439)
vulnerability in eclipse (CVE-2026-16439). Data can be tampered with by attackers.
|
| CVE-2026-21577 |
|
Vulnerability in dos (CVE-2026-21577)
vulnerability in dos (CVE-2026-21577). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16243 |
|
Out-of-Bounds Read in eclipse (CVE-2026-16243)
vulnerability in eclipse (CVE-2026-16243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16493 |
|
Vulnerability in CVE-2026-16493 (CVE-2026-16493)
vulnerability in CVE-2026-16493 (CVE-2026-16493). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21575 |
|
Code Injection in atlassian (CVE-2026-21575)
code injection in atlassian (CVE-2026-21575). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15432 |
|
Vulnerability in c (CVE-2026-15432)
vulnerability in c (CVE-2026-15432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15342 |
|
Vulnerability in CVE-2026-15342 (CVE-2026-15342)
vulnerability in CVE-2026-15342 (CVE-2026-15342). Data can be tampered with by attackers.
|
| CVE-2026-15829 |
|
SQL Injection in c (CVE-2026-15829)
SQL injection in c (CVE-2026-15829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15724 |
|
Vulnerability in path-traversal (CVE-2026-15724)
vulnerability in path-traversal (CVE-2026-15724). Confidential information can be exposed externally.
|
| CVE-2026-16454 |
|
Vulnerability in privilege-escalation (CVE-2026-16454)
vulnerability in privilege-escalation (CVE-2026-16454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24232 |
|
Unsafe Deserialization in deserialization (CVE-2026-24232)
vulnerability in deserialization (CVE-2026-24232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64825 |
|
Path Traversal in homeassistant (CVE-2026-64825)
path traversal in homeassistant (CVE-2026-64825). Data can be tampered with by attackers. Mitigation: upgrade to `2026.6.0` or later.
|
| CVE-2025-68640 |
|
Authentication Bypass in CVE-2025-68640 (CVE-2025-68640)
authentication bypass in CVE-2025-68640 (CVE-2025-68640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16451 |
|
Vulnerability in CVE-2026-16451 (CVE-2026-16451)
vulnerability in CVE-2026-16451 (CVE-2026-16451). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56585 |
|
Vulnerability in hcltech (CVE-2026-56585)
vulnerability in hcltech (CVE-2026-56585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64824 |
|
Path Traversal in path-traversal (CVE-2026-64824)
path traversal in path-traversal (CVE-2026-64824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28321 |
|
Vulnerability in solarwinds (CVE-2026-28321)
vulnerability in solarwinds (CVE-2026-28321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28312 |
|
Vulnerability in privilege-escalation (CVE-2026-28312)
vulnerability in privilege-escalation (CVE-2026-28312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28315 |
|
Cross-Site Scripting (XSS) in solarwinds (CVE-2026-28315)
cross-site scripting in solarwinds (CVE-2026-28315). Confidential information can be exposed externally.
|
| CVE-2026-64823 |
|
Cross-Site Scripting (XSS) in CVE-2026-64823 (CVE-2026-64823)
cross-site scripting in CVE-2026-64823 (CVE-2026-64823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16449 |
|
Vulnerability in sqli (CVE-2026-16449)
vulnerability in sqli (CVE-2026-16449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28310 |
|
Vulnerability in privilege-escalation (CVE-2026-28310)
vulnerability in privilege-escalation (CVE-2026-28310). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28309 |
|
Vulnerability in solarwinds (CVE-2026-28309)
vulnerability in solarwinds (CVE-2026-28309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28304 |
|
Vulnerability in solarwinds (CVE-2026-28304)
vulnerability in solarwinds (CVE-2026-28304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28306 |
|
Vulnerability in privilege-escalation (CVE-2026-28306)
vulnerability in privilege-escalation (CVE-2026-28306). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28307 |
|
Vulnerability in privilege-escalation (CVE-2026-28307)
vulnerability in privilege-escalation (CVE-2026-28307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16450 |
|
Vulnerability in CVE-2026-16450 (CVE-2026-16450)
vulnerability in CVE-2026-16450 (CVE-2026-16450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47657 |
|
Vulnerability in CVE-2026-47657 (CVE-2026-47657)
vulnerability in CVE-2026-47657 (CVE-2026-47657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15792 |
|
Vulnerability in mobyproject (CVE-2026-15792)
vulnerability in mobyproject (CVE-2026-15792). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15793 |
|
Vulnerability in mobyproject (CVE-2026-15793)
vulnerability in mobyproject (CVE-2026-15793). Data can be tampered with by attackers.
|
| CVE-2026-15789 |
|
Path Traversal in mobyproject (CVE-2026-15789)
path traversal in mobyproject (CVE-2026-15789). Data can be tampered with by attackers.
|
| CVE-2026-15791 |
|
Path Traversal in c (CVE-2026-15791)
path traversal in c (CVE-2026-15791). Data can be tampered with by attackers.
|
| CVE-2026-61884 |
|
Vulnerability in cisa (CVE-2026-61884)
vulnerability in cisa (CVE-2026-61884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8933 |
|
Vulnerability in privilege-escalation (CVE-2026-8933)
vulnerability in privilege-escalation (CVE-2026-8933). Successful exploitation can lead to full system takeover.
|