Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-73266 A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by ma… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-59765 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-59109 SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-58507 Private Repository Existence Disclosure via go-get Meta Endpoint No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-58443 Public-only repository tokens can update private PR head branches No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL No fix yet Fix from $4,0002026-08-13 MEDIUM 6.8 CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-58437 Repository Visibility Manipulation via Git Push Options No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting No fix yet Fix from $5,7502026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58417 REST API exposes organization membership of private organizations to public No fix yet Fix from $4,9002026-08-13 HIGH 7.7 CVE-2026-58314 Two SSRF findings in Gitea 1.26.2 No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-58416 Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs No fix yet Fix from $4,0002026-08-13 HIGH 8.5 CVE-2026-57894 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API No fix yet Fix from $5,7502026-08-13 CRITICAL 9.6 CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) No fix yet Fix from $4,9002026-08-13 MEDIUM 6.2 CVE-2026-56755 Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload No fix yet Fix from $4,0002026-08-13