Total
7905 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58440 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | |||||
| CVE-2026-56654 | 2026-08-26 | N/A | 9.8 CRITICAL | ||
| Privilege Escalation via Access Token Scope Escalation in API | |||||
| CVE-2026-55984 | 2026-08-26 | N/A | 2.7 LOW | ||
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | |||||
| CVE-2026-58439 | 2026-08-26 | N/A | 8.1 HIGH | ||
| Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | |||||
| CVE-2026-56755 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | |||||
| CVE-2026-56657 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Gitea SSH Key Parser Denial of Service | |||||
| CVE-2026-58507 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| Private Repository Existence Disclosure via go-get Meta Endpoint | |||||
| CVE-2026-58420 | 2026-08-26 | N/A | 4.4 MEDIUM | ||
| Local File Inclusion via file:// URI in Migration Restore | |||||
| CVE-2026-56750 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session | |||||
| CVE-2026-58437 | 2026-08-26 | N/A | 7.1 HIGH | ||
| Repository Visibility Manipulation via Git Push Options | |||||
| CVE-2026-58429 | 2026-08-26 | N/A | 4.9 MEDIUM | ||
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | |||||
| CVE-2026-58508 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |||||
| CVE-2026-55979 | 2026-08-26 | N/A | 5.2 MEDIUM | ||
| An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies. | |||||
| CVE-2026-55978 | 2026-08-26 | N/A | 8.4 HIGH | ||
| An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement. | |||||
| CVE-2026-67283 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension. | |||||
| CVE-2026-75950 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |||||
| CVE-2026-66494 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically.. | |||||
| CVE-2026-77997 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions. | |||||
| CVE-2026-67284 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users. | |||||
| CVE-2026-76599 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns. | |||||
