Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-56443 | 2026-08-26 | N/A | 9.6 CRITICAL | ||
| Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | |||||
| CVE-2026-24059 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code. | |||||
| CVE-2026-58420 | 2026-08-26 | N/A | 4.4 MEDIUM | ||
| Local File Inclusion via file:// URI in Migration Restore | |||||
| CVE-2026-56750 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session | |||||
| CVE-2026-58435 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| Gitea LFS Deploy-Key Privilege Escalation | |||||
| CVE-2026-58416 | 2026-08-26 | N/A | 7.1 HIGH | ||
| Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | |||||
| CVE-2026-58437 | 2026-08-26 | N/A | 7.1 HIGH | ||
| Repository Visibility Manipulation via Git Push Options | |||||
| CVE-2026-23603 | 2026-08-26 | N/A | 3.1 LOW | ||
| Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | |||||
| CVE-2026-55982 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | |||||
| CVE-2026-58438 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | |||||
| CVE-2026-58428 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | |||||
| CVE-2026-58429 | 2026-08-26 | N/A | 4.9 MEDIUM | ||
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | |||||
| CVE-2026-58508 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |||||
| CVE-2026-58444 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | |||||
| CVE-2026-58431 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| Public-only API token restriction is not enforced on team API routes | |||||
| CVE-2026-58314 | 2026-08-26 | N/A | 7.7 HIGH | ||
| Two SSRF findings in Gitea 1.26.2 | |||||
| CVE-2026-50105 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | |||||
| CVE-2026-66300 | 2026-08-26 | N/A | 5.0 MEDIUM | ||
| SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3. | |||||
| CVE-2026-73669 | 2026-08-26 | N/A | 7.3 HIGH | ||
| The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010. | |||||
| CVE-2026-75933 | 2026-08-26 | N/A | 7.3 HIGH | ||
| Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain. | |||||
