Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-57993Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-06
CVE-2026-57992Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57991Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high
2026-07-07
CVE-2026-57988Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57987Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-57986Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57985Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57984Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57983Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
critical
2026-07-07
CVE-2026-57981Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57977Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high
2026-07-07
CVE-2026-57975Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-57974Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-56646Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-56645Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high
2026-07-07
CVE-2026-55945Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
medium
2026-07-07
CVE-2026-45489Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
2026-07-12
CVE-2026-45488User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-07
CVE-2026-28744Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
high
2026-07-06
CVE-2026-28740Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
high
2026-07-07
CVE-2026-28737Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
high
2026-07-07
CVE-2026-28705Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
medium
2026-07-07
CVE-2026-28699Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
high
2026-07-06
CVE-2026-27783Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
medium
2026-07-06
CVE-2026-27780Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
critical
2026-07-06
CVE-2026-27779Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
high
2026-07-06
CVE-2026-27775Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.
high
2026-07-06
CVE-2026-27771Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
high
2026-07-07
CVE-2026-27761Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
medium
2026-07-07
CVE-2026-27660Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
high
2026-07-07
CVE-2026-27657Gitea versions before 1.25.5 allow a user to change another user's primary email address.
high
2026-07-07
CVE-2026-26307Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
high
2026-07-09
CVE-2026-26292Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
critical
2026-07-07
CVE-2026-26247Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
critical
2026-07-07
CVE-2026-26232Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
critical
2026-07-07
CVE-2026-26231Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
high
2026-07-07
CVE-2026-25782Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.
medium
2026-07-07
CVE-2026-25779Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
medium
2026-07-07
CVE-2026-25718Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
critical
2026-07-07
CVE-2026-25714Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
medium
2026-07-07
CVE-2026-25712Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
high
2026-07-07
CVE-2026-25038Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
high
2026-07-07
CVE-2026-24690Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
high
2026-07-07
CVE-2026-24451Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
high
2026-07-07
CVE-2026-22874Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
critical
2026-07-07
CVE-2026-22555Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
high
2026-07-06
CVE-2026-22547Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.
critical
2026-07-07
CVE-2026-20909Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
medium
2026-07-07
CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
critical
2026-07-07
CVE-2026-20779Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
high
2026-07-07