Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-73266
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by ma…
No fix yet
HIGH 7.5
CVE-2026-59765
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
No fix yet
HIGH 8.8
CVE-2026-59109
SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a rece…
No fix yet
CRITICAL 9.1
CVE-2026-58508
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
No fix yet
MEDIUM 5.3
CVE-2026-58507
Private Repository Existence Disclosure via go-get Meta Endpoint
No fix yet
CRITICAL 9.1
CVE-2026-58443
Public-only repository tokens can update private PR head branches
No fix yet
MEDIUM 6.5
CVE-2026-58442
Repository migration SSRF via multi-answer DNS allow-list bypass
No fix yet
MEDIUM 6.3
CVE-2026-58441
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
No fix yet
MEDIUM 6.8
CVE-2026-58440
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet…
No fix yet
HIGH 8.1
CVE-2026-58439
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
No fix yet
HIGH 7.5
CVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
No fix yet
HIGH 7.1
CVE-2026-58437
Repository Visibility Manipulation via Git Push Options
No fix yet
HIGH 7.5
CVE-2026-58436
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
No fix yet
MEDIUM 5.4
CVE-2026-58435
Gitea LFS Deploy-Key Privilege Escalation
No fix yet
HIGH 7.5
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
No fix yet
CRITICAL 9.1
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
No fix yet
MEDIUM 5.9
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …
No fix yet
MEDIUM 6.5
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
No fix yet
HIGH 7.5
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
No fix yet
HIGH 7.5
CVE-2026-58417
REST API exposes organization membership of private organizations to public
No fix yet
HIGH 7.7
CVE-2026-58314
Two SSRF findings in Gitea 1.26.2
No fix yet
HIGH 7.1
CVE-2026-58416
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
No fix yet
MEDIUM 6.5
CVE-2026-57897
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
No fix yet
HIGH 8.5
CVE-2026-57894
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
No fix yet
MEDIUM 5.9
CVE-2026-57886
Cross-repository issue/comment attachment re-linking can expose private attachment content
No fix yet
CRITICAL 9.1
CVE-2026-56750
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
No fix yet
CRITICAL 9.8
CVE-2026-56654
Privilege Escalation via Access Token Scope Escalation in API
No fix yet
CRITICAL 9.6
CVE-2026-56443
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
No fix yet
HIGH 8.1
CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
No fix yet
MEDIUM 6.2
CVE-2026-56755
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
No fix yet