Search

Search Results (377116 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-58442 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58444 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-59765 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-67614 1 Usmannasir 1 Cyberpanel 2026-08-13 9.8 Critical
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
CVE-2026-58417 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
REST API exposes organization membership of private organizations to public
CVE-2026-58425 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58428 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58429 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58431 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Public-only API token restriction is not enforced on team API routes
CVE-2026-58432 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58433 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58435 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58436 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58438 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58440 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58441 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58508 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-19745 1 Calix 1 Gigaspire 2026-08-13 4.3 Medium
A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-73669 2026-08-13 6.3 Medium
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.
CVE-2026-62888 1 Microsoft 14 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 11 more 2026-08-13 7.8 High
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.