Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-58597Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58524Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58522Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
medium
2026-07-07
CVE-2026-58426Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
critical
2026-07-06
CVE-2026-58424Permanent Fork PR Workflow Approval Gate Bypass
high
2026-07-06
CVE-2026-58423LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
high
2026-07-06
CVE-2026-58422Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
high
2026-07-06
CVE-2026-58421Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
high
2026-07-06
CVE-2026-58419Notification API leaks private issue metadata after access revocation
high
2026-07-06
CVE-2026-58418SSRF via HTTP Redirect in Repository Migration
medium
2026-07-06
CVE-2026-58300Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
medium
2026-07-07
CVE-2026-58299Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58298Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-58297Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-58296Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-58295Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
high
2026-07-07
CVE-2026-58294Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58293External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58292Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58291Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
medium
2026-07-06
CVE-2026-58290Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58289Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58288Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58287Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58286Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-58285Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58284Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58283Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58282Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58278Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58276Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57993Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-06
CVE-2026-57992Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57991Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-57988Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57987Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-57986Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57985Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57984Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57983Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
critical
2026-07-07
CVE-2026-57981Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57977Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-07
CVE-2026-57975Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57974Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-56646Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-56645Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-55945Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
medium
2026-07-07
CVE-2026-45489Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
2026-07-12
CVE-2026-45488User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-28744Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
high
2026-07-06