Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57993 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57993)
SSRF in ssrf (CVE-2026-57993). Confidential information can be exposed externally.
|
| CVE-2026-58276 |
|
Use-After-Free in microsoft (CVE-2026-58276)
vulnerability in microsoft (CVE-2026-58276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57992 |
|
Use-After-Free in microsoft (CVE-2026-57992)
vulnerability in microsoft (CVE-2026-57992). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57991 |
|
Vulnerability in microsoft (CVE-2026-57991)
vulnerability in microsoft (CVE-2026-57991). Confidential information can be exposed externally.
|
| CVE-2026-58282 |
|
Vulnerability in microsoft (CVE-2026-58282)
vulnerability in microsoft (CVE-2026-58282). Data can be tampered with by attackers.
|
| CVE-2026-57988 |
|
Vulnerability in path-traversal (CVE-2026-57988)
vulnerability in path-traversal (CVE-2026-57988). Data can be tampered with by attackers.
|
| CVE-2026-57986 |
|
Use-After-Free in microsoft (CVE-2026-57986)
vulnerability in microsoft (CVE-2026-57986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56645 |
|
Vulnerability in microsoft (CVE-2026-56645)
vulnerability in microsoft (CVE-2026-56645). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57974 |
|
Vulnerability in microsoft (CVE-2026-57974)
vulnerability in microsoft (CVE-2026-57974). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57975 |
|
Vulnerability in microsoft (CVE-2026-57975)
vulnerability in microsoft (CVE-2026-57975). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27779 |
|
Vulnerability in CVE-2026-27779 (CVE-2026-27779)
vulnerability in CVE-2026-27779 (CVE-2026-27779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57985 |
|
Vulnerability in microsoft (CVE-2026-57985)
vulnerability in microsoft (CVE-2026-57985). Data can be tampered with by attackers.
|
| CVE-2026-57984 |
|
Use-After-Free in microsoft (CVE-2026-57984)
vulnerability in microsoft (CVE-2026-57984). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57977 |
|
Cross-Site Scripting (XSS) in microsoft (CVE-2026-57977)
cross-site scripting in microsoft (CVE-2026-57977). Data can be tampered with by attackers.
|
| CVE-2026-57983 |
|
Vulnerability in microsoft (CVE-2026-57983)
vulnerability in microsoft (CVE-2026-57983). Confidential information can be exposed externally.
|
| CVE-2026-57981 |
|
Use-After-Free in microsoft (CVE-2026-57981)
vulnerability in microsoft (CVE-2026-57981). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27660 |
|
Vulnerability in CVE-2026-27660 (CVE-2026-27660)
vulnerability in CVE-2026-27660 (CVE-2026-27660). Data can be tampered with by attackers.
|
| CVE-2026-26307 |
|
Vulnerability in CVE-2026-26307 (CVE-2026-26307)
vulnerability in CVE-2026-26307 (CVE-2026-26307). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25712 |
|
Vulnerability in CVE-2026-25712 (CVE-2026-25712)
vulnerability in CVE-2026-25712 (CVE-2026-25712). Confidential information can be exposed externally.
|
| CVE-2026-27657 |
|
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
|
| CVE-2026-24690 |
|
Vulnerability in CVE-2026-24690 (CVE-2026-24690)
vulnerability in CVE-2026-24690 (CVE-2026-24690). Data can be tampered with by attackers.
|
| CVE-2026-58424 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58424)
vulnerability in code.gitea.io/gitea (CVE-2026-58424). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-58421 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58421)
vulnerability in code.gitea.io/gitea (CVE-2026-58421). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/repos/{owner}/{repo}/pulls`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-58423 |
|
Authentication Bypass in code.gitea.io/gitea (CVE-2026-58423)
authentication bypass in code.gitea.io/gitea (CVE-2026-58423). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-58419 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-58419)
vulnerability in code.gitea.io/gitea (CVE-2026-58419). Confidential information can be exposed externally. Exploitable via `GET /api/v1/repos/sun/{repo}/issues/1`. Mitigation: upgrade to `1.25.4` or later.
|
| CVE-2026-28740 |
|
Vulnerability in gitea.dev (CVE-2026-28740)
vulnerability in gitea.dev (CVE-2026-28740). Confidential information can be exposed externally. Exploitable via ``unit.TypeInvalid``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-27775 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-27775)
vulnerability in code.gitea.io/gitea (CVE-2026-27775). Successful exploitation can lead to full system takeover. Exploitable via `POST /{owner}/{repo}.git/git-receive-pack`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-27771 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-27771)
vulnerability in code.gitea.io/gitea (CVE-2026-27771). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-25038 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-25038)
vulnerability in code.gitea.io/gitea (CVE-2026-25038). Confidential information can be exposed externally. Exploitable via `GET /api/v1/orgs/{org}/labels`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-24451 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-24451)
vulnerability in code.gitea.io/gitea (CVE-2026-24451). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/{owner}/{repo}/merge-upstream`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-20779 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-20779)
vulnerability in code.gitea.io/gitea (CVE-2026-20779). Confidential information can be exposed externally. Exploitable via `POST /user/two_factor`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-14606 |
|
Buffer Overflow in CVE-2026-14606 (CVE-2026-14606)
vulnerability in CVE-2026-14606 (CVE-2026-14606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14605 |
|
Buffer Overflow in CVE-2026-14605 (CVE-2026-14605)
vulnerability in CVE-2026-14605 (CVE-2026-14605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58379 |
|
Vulnerability in dos (CVE-2026-58379)
vulnerability in dos (CVE-2026-58379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53478 |
|
OS Command Injection in dell (CVE-2026-53478)
OS command injection in dell (CVE-2026-53478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49815 |
|
OS Command Injection in dell (CVE-2026-49815)
OS command injection in dell (CVE-2026-49815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49814 |
|
OS Command Injection in dell (CVE-2026-49814)
OS command injection in dell (CVE-2026-49814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14460 |
|
Vulnerability in CVE-2026-14460 (CVE-2026-14460)
vulnerability in CVE-2026-14460 (CVE-2026-14460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14459 |
|
Vulnerability in CVE-2026-14459 (CVE-2026-14459)
vulnerability in CVE-2026-14459 (CVE-2026-14459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13341 |
|
Vulnerability in CVE-2026-13341 (CVE-2026-13341)
vulnerability in CVE-2026-13341 (CVE-2026-13341). Confidential information can be exposed externally.
|
| CVE-2026-10055 |
|
Information Disclosure in CVE-2026-10055 (CVE-2026-10055)
vulnerability in CVE-2026-10055 (CVE-2026-10055). Confidential information can be exposed externally.
|
| CVE-2026-10054 |
|
Vulnerability in CVE-2026-10054 (CVE-2026-10054)
vulnerability in CVE-2026-10054 (CVE-2026-10054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-9148 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9148)
cross-site scripting in wordpress (CVE-2026-9148). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-9547 |
|
Vulnerability in haxx (CVE-2026-9547)
vulnerability in haxx (CVE-2026-9547). Confidential information can be exposed externally. Exploitable via ``CURLOPT_SSH_KEYFUNCTION``.
|
| CVE-2026-9546 |
|
Vulnerability in haxx (CVE-2026-9546)
vulnerability in haxx (CVE-2026-9546). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REFERER``.
|
| CVE-2026-9545 |
|
Vulnerability in haxx (CVE-2026-9545)
vulnerability in haxx (CVE-2026-9545). Confidential information can be exposed externally. Exploitable via ``CURLOPT_SSL_SESSIONID_CACHE``.
|
| CVE-2026-8932 |
|
Vulnerability in haxx (CVE-2026-8932)
vulnerability in haxx (CVE-2026-8932). Data can be tampered with by attackers.
|
| CVE-2026-9080 |
|
Use-After-Free in haxx (CVE-2026-9080)
vulnerability in haxx (CVE-2026-9080). Risk of unauthorized operations or information disclosure. Exploitable via ``CURLMOPT_SOCKETFUNCTION``.
|