Total
7696 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-62609 | 1 Oracle | 1 Reports Developer | 2026-08-26 | N/A | 9.8 CRITICAL |
| Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |||||
| CVE-2026-62608 | 1 Oracle | 1 Reports Developer | 2026-08-26 | N/A | 9.9 CRITICAL |
| Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). | |||||
| CVE-2026-58417 | 2026-08-26 | N/A | 7.5 HIGH | ||
| REST API exposes organization membership of private organizations to public | |||||
| CVE-2026-59763 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | |||||
| CVE-2026-55986 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| Email Management API Bypasses ManageCredentials Feature Restrictions | |||||
| CVE-2026-58440 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | |||||
| CVE-2026-56654 | 2026-08-26 | N/A | 9.8 CRITICAL | ||
| Privilege Escalation via Access Token Scope Escalation in API | |||||
| CVE-2026-55984 | 2026-08-26 | N/A | 2.7 LOW | ||
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | |||||
| CVE-2026-58439 | 2026-08-26 | N/A | 8.1 HIGH | ||
| Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | |||||
| CVE-2026-56755 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | |||||
| CVE-2026-56657 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Gitea SSH Key Parser Denial of Service | |||||
| CVE-2026-58507 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| Private Repository Existence Disclosure via go-get Meta Endpoint | |||||
| CVE-2026-58420 | 2026-08-26 | N/A | 4.4 MEDIUM | ||
| Local File Inclusion via file:// URI in Migration Restore | |||||
| CVE-2026-56750 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session | |||||
| CVE-2026-58437 | 2026-08-26 | N/A | 7.1 HIGH | ||
| Repository Visibility Manipulation via Git Push Options | |||||
| CVE-2026-58429 | 2026-08-26 | N/A | 4.9 MEDIUM | ||
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | |||||
| CVE-2026-58508 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |||||
| CVE-2026-55979 | 2026-08-26 | N/A | 5.2 MEDIUM | ||
| An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies. | |||||
| CVE-2026-55978 | 2026-08-26 | N/A | 8.4 HIGH | ||
| An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement. | |||||
| CVE-2026-67283 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension. | |||||
