Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57983 |
|
Vulnerability in microsoft (CVE-2026-57983)
vulnerability in microsoft (CVE-2026-57983). Confidential information can be exposed externally.
|
| CVE-2026-57986 |
|
Use-After-Free in microsoft (CVE-2026-57986)
vulnerability in microsoft (CVE-2026-57986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27660 |
|
Vulnerability in CVE-2026-27660 (CVE-2026-27660)
vulnerability in CVE-2026-27660 (CVE-2026-27660). Data can be tampered with by attackers.
|
| CVE-2026-24690 |
|
Vulnerability in CVE-2026-24690 (CVE-2026-24690)
vulnerability in CVE-2026-24690 (CVE-2026-24690). Data can be tampered with by attackers.
|
| CVE-2026-25712 |
|
Vulnerability in CVE-2026-25712 (CVE-2026-25712)
vulnerability in CVE-2026-25712 (CVE-2026-25712). Confidential information can be exposed externally.
|
| CVE-2026-27657 |
|
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
|
| CVE-2026-26307 |
|
Vulnerability in CVE-2026-26307 (CVE-2026-26307)
vulnerability in CVE-2026-26307 (CVE-2026-26307). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58424 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58424)
vulnerability in code.gitea.io/gitea (CVE-2026-58424). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-58423 |
|
Authentication Bypass in code.gitea.io/gitea (CVE-2026-58423)
authentication bypass in code.gitea.io/gitea (CVE-2026-58423). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-58421 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58421)
vulnerability in code.gitea.io/gitea (CVE-2026-58421). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/repos/{owner}/{repo}/pulls`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-58419 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-58419)
vulnerability in code.gitea.io/gitea (CVE-2026-58419). Confidential information can be exposed externally. Exploitable via `GET /api/v1/repos/sun/{repo}/issues/1`. Mitigation: upgrade to `1.25.4` or later.
|
| CVE-2026-27771 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-27771)
vulnerability in code.gitea.io/gitea (CVE-2026-27771). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-28740 |
|
Vulnerability in gitea.dev (CVE-2026-28740)
vulnerability in gitea.dev (CVE-2026-28740). Confidential information can be exposed externally. Exploitable via ``unit.TypeInvalid``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-27775 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-27775)
vulnerability in code.gitea.io/gitea (CVE-2026-27775). Successful exploitation can lead to full system takeover. Exploitable via `POST /{owner}/{repo}.git/git-receive-pack`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-24451 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-24451)
vulnerability in code.gitea.io/gitea (CVE-2026-24451). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/{owner}/{repo}/merge-upstream`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-25038 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-25038)
vulnerability in code.gitea.io/gitea (CVE-2026-25038). Confidential information can be exposed externally. Exploitable via `GET /api/v1/orgs/{org}/labels`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-20779 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-20779)
vulnerability in code.gitea.io/gitea (CVE-2026-20779). Confidential information can be exposed externally. Exploitable via `POST /user/two_factor`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-14605 |
|
Buffer Overflow in CVE-2026-14605 (CVE-2026-14605)
vulnerability in CVE-2026-14605 (CVE-2026-14605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14606 |
|
Buffer Overflow in CVE-2026-14606 (CVE-2026-14606)
vulnerability in CVE-2026-14606 (CVE-2026-14606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58379 |
|
Vulnerability in dos (CVE-2026-58379)
vulnerability in dos (CVE-2026-58379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49815 |
|
OS Command Injection in dell (CVE-2026-49815)
OS command injection in dell (CVE-2026-49815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53478 |
|
OS Command Injection in dell (CVE-2026-53478)
OS command injection in dell (CVE-2026-53478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49814 |
|
OS Command Injection in dell (CVE-2026-49814)
OS command injection in dell (CVE-2026-49814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14459 |
|
Vulnerability in CVE-2026-14459 (CVE-2026-14459)
vulnerability in CVE-2026-14459 (CVE-2026-14459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14460 |
|
Vulnerability in CVE-2026-14460 (CVE-2026-14460)
vulnerability in CVE-2026-14460 (CVE-2026-14460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13341 |
|
Vulnerability in CVE-2026-13341 (CVE-2026-13341)
vulnerability in CVE-2026-13341 (CVE-2026-13341). Confidential information can be exposed externally.
|
| CVE-2026-10055 |
|
Information Disclosure in CVE-2026-10055 (CVE-2026-10055)
vulnerability in CVE-2026-10055 (CVE-2026-10055). Confidential information can be exposed externally.
|
| CVE-2026-10054 |
|
Vulnerability in CVE-2026-10054 (CVE-2026-10054)
vulnerability in CVE-2026-10054 (CVE-2026-10054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-9148 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9148)
cross-site scripting in wordpress (CVE-2026-9148). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-9547 |
|
Vulnerability in haxx (CVE-2026-9547)
vulnerability in haxx (CVE-2026-9547). Confidential information can be exposed externally. Exploitable via ``CURLOPT_SSH_KEYFUNCTION``.
|
| CVE-2026-9546 |
|
Vulnerability in haxx (CVE-2026-9546)
vulnerability in haxx (CVE-2026-9546). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REFERER``.
|
| CVE-2026-9545 |
|
Vulnerability in haxx (CVE-2026-9545)
vulnerability in haxx (CVE-2026-9545). Confidential information can be exposed externally. Exploitable via ``CURLOPT_SSL_SESSIONID_CACHE``.
|
| CVE-2026-9080 |
|
Use-After-Free in haxx (CVE-2026-9080)
vulnerability in haxx (CVE-2026-9080). Risk of unauthorized operations or information disclosure. Exploitable via ``CURLMOPT_SOCKETFUNCTION``.
|
| CVE-2026-8932 |
|
Vulnerability in haxx (CVE-2026-8932)
vulnerability in haxx (CVE-2026-8932). Data can be tampered with by attackers.
|
| CVE-2026-8286 |
|
Vulnerability in haxx (CVE-2026-8286)
vulnerability in haxx (CVE-2026-8286). Confidential information can be exposed externally.
|
| CVE-2026-12064 |
|
Vulnerability in haxx (CVE-2026-12064)
vulnerability in haxx (CVE-2026-12064). Data can be tampered with by attackers.
|
| CVE-2026-4967 |
|
Vulnerability in dos (CVE-2026-4967)
vulnerability in dos (CVE-2026-4967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11586 |
|
Vulnerability in haxx (CVE-2026-11586)
vulnerability in haxx (CVE-2026-11586). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11352 |
|
Vulnerability in dos (CVE-2026-11352)
vulnerability in dos (CVE-2026-11352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13040 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13040)
cross-site scripting in wordpress (CVE-2026-13040). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14352 |
|
Path Traversal in wordpress (CVE-2026-14352)
path traversal in wordpress (CVE-2026-14352). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-14327 |
|
Path Traversal in wordpress (CVE-2026-14327)
path traversal in wordpress (CVE-2026-14327). Confidential information can be exposed externally.
|
| CVE-2026-8247 |
|
Vulnerability in watchguard (CVE-2026-8247)
vulnerability in watchguard (CVE-2026-8247). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13368 |
|
Use-After-Free in watchguard (CVE-2026-13368)
vulnerability in watchguard (CVE-2026-13368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13722 |
|
Vulnerability in watchguard (CVE-2026-13722)
vulnerability in watchguard (CVE-2026-13722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13384 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13384)
out-of-bounds write in watchguard (CVE-2026-13384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13383 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13383)
out-of-bounds write in watchguard (CVE-2026-13383). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13084 |
|
Vulnerability in dos (CVE-2026-13084)
vulnerability in dos (CVE-2026-13084). Risk of unauthorized operations or information disclosure.
|