Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-58298Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-58297Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-58296Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-58295Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
high
2026-07-07
CVE-2026-58294Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58293External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58292Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58291Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
medium
2026-07-06
CVE-2026-58290Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58289Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58288Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58287Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58286Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-58285Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58284Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-58283Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58282Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58278Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-06
CVE-2026-58276Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57993Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-06
CVE-2026-57992Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57991Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-57988Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57987Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-57986Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57985Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57984Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57983Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
critical
2026-07-07
CVE-2026-57981Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57977Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-07
CVE-2026-57975Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57974Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-56646Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-56645Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-55945Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
medium
2026-07-07
CVE-2026-45489Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
2026-07-12
CVE-2026-45488User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-28744Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
high
2026-07-06
CVE-2026-28740Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
high
2026-07-07
CVE-2026-28737Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
high
2026-07-07
CVE-2026-28705Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
medium
2026-07-07
CVE-2026-28699Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
high
2026-07-06
CVE-2026-27783Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
medium
2026-07-06
CVE-2026-27780Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
critical
2026-07-06
CVE-2026-27779Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
high
2026-07-06
CVE-2026-27775Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.
high
2026-07-06
CVE-2026-27771Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
high
2026-07-07
CVE-2026-27761Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
medium
2026-07-07
CVE-2026-27660Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
high
2026-07-07
CVE-2026-27657Gitea versions before 1.25.5 allow a user to change another user's primary email address.
high
2026-07-07