Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10680 |
|
Out-of-Bounds Read in c (CVE-2026-10680)
vulnerability in c (CVE-2026-10680). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59765 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-59765)
SSRF in code.gitea.io/gitea (CVE-2026-59765). Confidential information can be exposed externally. Exploitable via ``DefaultClient``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58427 |
|
Information Disclosure in gitea.dev (CVE-2026-58427)
vulnerability in gitea.dev (CVE-2026-58427). Confidential information can be exposed externally. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-8982 |
|
Vulnerability in autel (CVE-2026-8982)
vulnerability in autel (CVE-2026-8982). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65056 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-65056 (CVE-2026-65056)
SSRF in CVE-2026-65056 (CVE-2026-65056). Confidential information can be exposed externally.
|
| CVE-2026-64881 |
|
OS Command Injection in tenable (CVE-2026-64881)
OS command injection in tenable (CVE-2026-64881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44878 |
|
Vulnerability in CVE-2026-44878 (CVE-2026-44878)
vulnerability in CVE-2026-44878 (CVE-2026-44878). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56147 |
|
Vulnerability in elastic (CVE-2026-56147)
vulnerability in elastic (CVE-2026-56147). Confidential information can be exposed externally.
|
| CVE-2026-63764 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63764)
SSRF in ssrf (CVE-2026-63764). Confidential information can be exposed externally.
|
| CVE-2026-63358 |
|
Vulnerability in filegator (CVE-2026-63358)
vulnerability in filegator (CVE-2026-63358). Confidential information can be exposed externally.
|
| CVE-2026-52474 |
|
Information Disclosure in CVE-2026-52474 (CVE-2026-52474)
vulnerability in CVE-2026-52474 (CVE-2026-52474). Confidential information can be exposed externally.
|
| CVE-2026-30633 |
|
Path Traversal in path-traversal (CVE-2026-30633)
path traversal in path-traversal (CVE-2026-30633). Confidential information can be exposed externally.
|
| CVE-2026-44879 |
|
Command Injection in CVE-2026-44879 (CVE-2026-44879)
command injection in CVE-2026-44879 (CVE-2026-44879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52476 |
|
SQL Injection in sqli (CVE-2026-52476)
SQL injection in sqli (CVE-2026-52476). Confidential information can be exposed externally.
|
| CVE-2026-64880 |
|
SQL Injection in sqli (CVE-2026-64880)
SQL injection in sqli (CVE-2026-64880). Confidential information can be exposed externally.
|
| CVE-2026-59146 |
|
Out-of-Bounds Read in CVE-2026-59146 (CVE-2026-59146)
vulnerability in CVE-2026-59146 (CVE-2026-59146). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50757 |
|
Path Traversal in path-traversal (CVE-2026-50757)
path traversal in path-traversal (CVE-2026-50757). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50756 |
|
Vulnerability in CVE-2026-50756 (CVE-2026-50756)
vulnerability in CVE-2026-50756 (CVE-2026-50756). Confidential information can be exposed externally.
|
| CVE-2026-56852 |
|
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
|
| CVE-2026-50759 |
|
Vulnerability in CVE-2026-50759 (CVE-2026-50759)
vulnerability in CVE-2026-50759 (CVE-2026-50759). Risk of unauthorized operations or information disclosure. Exploitable via `GET /state`.
|
| CVE-2026-50758 |
|
Cross-Site Scripting (XSS) in CVE-2026-50758 (CVE-2026-50758)
cross-site scripting in CVE-2026-50758 (CVE-2026-50758). Confidential information can be exposed externally.
|
| CVE-2026-63454 |
|
Path Traversal in path-traversal (CVE-2026-63454)
path traversal in path-traversal (CVE-2026-63454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63453 |
|
Vulnerability in hpe (CVE-2026-63453)
vulnerability in hpe (CVE-2026-63453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46600 |
|
Out-of-Bounds Read in CVE-2026-46600 (CVE-2026-46600)
vulnerability in CVE-2026-46600 (CVE-2026-46600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64877 |
|
Vulnerability in sqli (CVE-2026-64877)
vulnerability in sqli (CVE-2026-64877). Confidential information can be exposed externally.
|
| CVE-2026-30632 |
|
Path Traversal in path-traversal (CVE-2026-30632)
path traversal in path-traversal (CVE-2026-30632). Confidential information can be exposed externally.
|
| CVE-2026-47697 |
|
Authorization Flaw in CVE-2026-47697 (CVE-2026-47697)
vulnerability in CVE-2026-47697 (CVE-2026-47697). Confidential information can be exposed externally. Exploitable via ``connect``.
|
| CVE-2026-47690 |
|
Command Injection in CVE-2026-47690 (CVE-2026-47690)
command injection in CVE-2026-47690 (CVE-2026-47690). Data can be tampered with by attackers. Exploitable via ``GITHUB_TOKEN``.
|
| CVE-2026-47685 |
|
Cross-Site Scripting (XSS) in fogproject (CVE-2026-47685)
cross-site scripting in fogproject (CVE-2026-47685). Confidential information can be exposed externally.
|
| CVE-2026-47688 |
|
Vulnerability in csrf (CVE-2026-47688)
vulnerability in csrf (CVE-2026-47688). Data can be tampered with by attackers. Exploitable via ``clearAES``.
|
| CVE-2026-47687 |
|
Cross-Site Scripting (XSS) in fogproject (CVE-2026-47687)
cross-site scripting in fogproject (CVE-2026-47687). Confidential information can be exposed externally. Exploitable via ``fogpage.class.php``.
|
| CVE-2026-47237 |
|
Vulnerability in CVE-2026-47237 (CVE-2026-47237)
vulnerability in CVE-2026-47237 (CVE-2026-47237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58314 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-58314)
SSRF in code.gitea.io/gitea (CVE-2026-58314). Confidential information can be exposed externally. Exploitable via `POST /api/v1/user/hooks`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58436 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58436)
vulnerability in code.gitea.io/gitea (CVE-2026-58436). Risk of unauthorized operations or information disclosure. Exploitable via ``main``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58437 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58437)
vulnerability in code.gitea.io/gitea (CVE-2026-58437). Data can be tampered with by attackers. Exploitable via ``repo.private``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-55987 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-55987)
vulnerability in code.gitea.io/gitea (CVE-2026-55987). Confidential information can be exposed externally. Exploitable via ``offline_access``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58434 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-58434)
vulnerability in code.gitea.io/gitea (CVE-2026-58434). Confidential information can be exposed externally. Exploitable via `GET /api/v1/user/starred`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-54481 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-54481)
vulnerability in code.gitea.io/gitea (CVE-2026-54481). Successful exploitation can lead to full system takeover. Exploitable via `Host header`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58417 |
|
Vulnerability in gitea.dev (CVE-2026-58417)
vulnerability in gitea.dev (CVE-2026-58417). Confidential information can be exposed externally. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58416 |
|
Vulnerability in gitea.dev (CVE-2026-58416)
vulnerability in gitea.dev (CVE-2026-58416). Confidential information can be exposed externally. Exploitable via `GET /userb/repoB.git/info/refs`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58438 |
|
Vulnerability in gitea.dev (CVE-2026-58438)
vulnerability in gitea.dev (CVE-2026-58438). Confidential information can be exposed externally. Exploitable via ``RemoveDependency``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-47667 |
|
Vulnerability in c (CVE-2026-47667)
vulnerability in c (CVE-2026-47667). Risk of unauthorized operations or information disclosure. Exploitable via ``fread``.
|
| CVE-2026-58439 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58439)
vulnerability in code.gitea.io/gitea (CVE-2026-58439). Data can be tampered with by attackers. Exploitable via ``official``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-15957 |
|
Vulnerability in Amazon aws (CVE-2026-15957)
vulnerability in Amazon aws (CVE-2026-15957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73650 |
|
Cross-Site Scripting (XSS) in svgo (CVE-2026-73650)
cross-site scripting in svgo (CVE-2026-73650). Confidential information can be exposed externally. Exploitable via ``script``. Mitigation: upgrade to `4.0.2` or later.
|
| CVE-2026-57894 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-57894)
SSRF in code.gitea.io/gitea (CVE-2026-57894). Confidential information can be exposed externally. Exploitable via `POST /repo/migrate`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-55084 |
|
SQL Injection in sqli (CVE-2026-55084)
SQL injection in sqli (CVE-2026-55084). Successful exploitation can lead to full system takeover. Exploitable via ``filter``.
|
| CVE-2026-44880 |
|
Vulnerability in hpe (CVE-2026-44880)
vulnerability in hpe (CVE-2026-44880). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21579 |
|
Information Disclosure in atlassian (CVE-2026-21579)
vulnerability in atlassian (CVE-2026-21579). Confidential information can be exposed externally.
|
| CVE-2026-21575 |
|
Code Injection in atlassian (CVE-2026-21575)
code injection in atlassian (CVE-2026-21575). Successful exploitation can lead to full system takeover.
|