Export limit exceeded: 369898 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (141 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-56657 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 6.2 Medium |
| Gitea SSH Key Parser Denial of Service | ||||
| CVE-2026-58510 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 4.3 Medium |
| GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||||
| CVE-2026-42931 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 6.5 Medium |
| Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | ||||
| CVE-2026-59763 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 4.3 Medium |
| Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||||
| CVE-2026-58511 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 2.7 Low |
| Webhook Authorization Header Returned in Plaintext via API | ||||
| CVE-2026-57897 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 6.5 Medium |
| Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | ||||
| CVE-2026-56755 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 6.2 Medium |
| Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | ||||
| CVE-2026-24791 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 8.1 High |
| Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | ||||
| CVE-2026-26307 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-09 | 7.5 High |
| Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources. | ||||
| CVE-2026-20779 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 7.1 High |
| Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path. | ||||
| CVE-2026-20896 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 9.8 Critical |
| Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | ||||
| CVE-2026-20909 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 5.3 Medium |
| Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. | ||||
| CVE-2026-22547 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 9.1 Critical |
| Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values. | ||||
| CVE-2026-22874 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 9.6 Critical |
| Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | ||||
| CVE-2026-24451 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 7.5 High |
| Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. | ||||
| CVE-2026-24690 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 7.5 High |
| Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. | ||||
| CVE-2026-25038 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 7.5 High |
| Gitea 1.26.2 allows unauthorized users to access labels of private organizations. | ||||
| CVE-2026-25712 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 7.5 High |
| Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. | ||||
| CVE-2026-25714 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 4.3 Medium |
| Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941. | ||||
| CVE-2026-25718 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-07-07 | 9.1 Critical |
| Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths. | ||||