| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73482 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central… | ||
| CVE-2026-73481 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET request (?page=bouncerules&del=N), and the central CSRF check (verifyCsrfGetToken) is invoked with… | ||
| CVE-2026-73038 | Med | 0.33 | 6.1 | 0.00 | Aug 13, 2026 | NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags to inject arbitrary HTML and… | ||
| CVE-2026-73037 | Med | 0.40 | 6.1 | 0.00 | Aug 13, 2026 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin,… | ||
| CVE-2026-72777 | Hig | 0.56 | 8.6 | 0.00 | Aug 13, 2026 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string… | ||
| CVE-2026-18071 | Hig | 0.51 | 7.8 | 0.00 | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. | ||
| CVE-2026-17220 | Hig | 0.53 | 8.2 | 0.01 | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. | ||
| CVE-2026-17197 | Hig | 0.53 | 8.1 | 0.01 | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. | ||
| CVE-2026-73649 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in… | ||
| CVE-2026-73648 | Med | 0.26 | — | 0.01 | Aug 13, 2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href… | ||
| CVE-2026-73647 | Med | 0.29 | 5.6 | 0.00 | Aug 13, 2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without… | ||
| CVE-2026-73645 | Med | 0.36 | — | 0.01 | Aug 13, 2026 | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap… | ||
| CVE-2026-73644 | Cri | 0.55 | 9.6 | 0.00 | Aug 13, 2026 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy… | ||
| CVE-2026-73643 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a… | ||
| CVE-2026-73569 | Hig | 0.50 | — | 0.01 | Aug 13, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through… | ||
| CVE-2026-73568 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against… | ||
| CVE-2026-73567 | Cri | 0.52 | 9.1 | 0.00 | Aug 13, 2026 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by [email protected], which… | ||
| CVE-2026-73566 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty… | ||
| CVE-2026-73565 | Med | 0.27 | 5.3 | 0.01 | Aug 13, 2026 | @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap… | ||
| CVE-2026-73564 | Hig | 0.50 | — | 0.01 | Aug 13, 2026 | frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats… | ||
| CVE-2026-73563 | Med | 0.24 | 4.7 | 0.00 | Aug 13, 2026 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for… | ||
| CVE-2026-73562 | Med | 0.35 | 6.5 | 0.01 | Aug 13, 2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted… | ||
| CVE-2026-73561 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request… | ||
| CVE-2026-72741 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token… | ||
| CVE-2026-67614 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a… | ||
| CVE-2026-67613 | Med | 0.25 | 4.9 | 0.01 | Aug 13, 2026 | CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter… | ||
| CVE-2026-19730 | Med | 0.20 | 4.2 | 0.00 | Aug 13, 2026 | The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in… | ||
| CVE-2026-18428 | Hig | 0.57 | 8.8 | 0.01 | Aug 13, 2026 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint. | ||
| CVE-2026-12908 | — | 0.00 | — | — | Aug 13, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. | ||
| CVE-2026-12236 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. The per-entry stride rsp->len is taken directly from the… | ||
| CVE-2024-58374 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2026 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet… | ||
| CVE-2019-25765 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2026 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword… | ||
| CVE-2026-73266 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant.… | ||
| CVE-2026-59765 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | ||
| CVE-2026-59763 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||
| CVE-2026-59109 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement… | ||
| CVE-2026-58511 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Webhook Authorization Header Returned in Plaintext via API | ||
| CVE-2026-58510 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2026-58508 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2026 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||
| CVE-2026-58507 | Med | 0.27 | 5.3 | 0.00 | Aug 13, 2026 | Private Repository Existence Disclosure via go-get Meta Endpoint | ||
| CVE-2026-58445 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||
| CVE-2026-58444 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||
| CVE-2026-58443 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Public-only repository tokens can update private PR head branches | ||
| CVE-2026-58442 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Repository migration SSRF via multi-answer DNS allow-list bypass | ||
| CVE-2026-58441 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | ||
| CVE-2026-58440 | Med | 0.37 | 6.8 | 0.00 | Aug 13, 2026 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | ||
| CVE-2026-58439 | Hig | 0.46 | 8.1 | 0.01 | Aug 13, 2026 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | ||
| CVE-2026-58438 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | ||
| CVE-2026-58437 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Repository Visibility Manipulation via Git Push Options | ||
| CVE-2026-58436 | Hig | 0.42 | 7.5 | 0.01 | Aug 13, 2026 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests |
- risk 0.46cvss 8.1epss 0.00
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central…
- risk 0.28cvss 5.4epss 0.00
phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET request (?page=bouncerules&del=N), and the central CSRF check (verifyCsrfGetToken) is invoked with…
- risk 0.33cvss 6.1epss 0.00
NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags to inject arbitrary HTML and…
- risk 0.40cvss 6.1epss 0.00
Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin,…
- risk 0.56cvss 8.6epss 0.00
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string…
- risk 0.51cvss 7.8epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.
- risk 0.53cvss 8.2epss 0.01
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
- risk 0.53cvss 8.1epss 0.01
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
- risk 0.57cvss 9.8epss 0.01
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in…
- risk 0.26cvss —epss 0.01
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href…
- risk 0.29cvss 5.6epss 0.00
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without…
- risk 0.36cvss —epss 0.01
OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap…
- risk 0.55cvss 9.6epss 0.00
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy…
- risk 0.42cvss 7.5epss 0.00
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a…
- risk 0.50cvss —epss 0.01
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through…
- risk 0.42cvss 7.5epss 0.00
py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against…
- risk 0.52cvss 9.1epss 0.00
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by [email protected], which…
- risk 0.42cvss 7.5epss 0.01
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty…
- risk 0.27cvss 5.3epss 0.01
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap…
- risk 0.50cvss —epss 0.01
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats…
- risk 0.24cvss 4.7epss 0.00
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for…
- risk 0.35cvss 6.5epss 0.01
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted…
- risk 0.42cvss 7.5epss 0.01
Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request…
- risk 0.53cvss 8.1epss 0.00
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token…
- risk 0.57cvss 9.8epss 0.01
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a…
- risk 0.25cvss 4.9epss 0.01
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter…
- risk 0.20cvss 4.2epss 0.00
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in…
- risk 0.57cvss 8.8epss 0.01
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
- CVE-2026-12908Aug 13, 2026risk 0.00cvss —epss —
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
- risk 0.35cvss 6.5epss 0.00
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. The per-entry stride rsp->len is taken directly from the…
- risk 0.49cvss 7.5epss 0.01
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet…
- risk 0.49cvss 7.5epss 0.01
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword…
- risk 0.46cvss 7.1epss 0.00
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant.…
- risk 0.42cvss 7.5epss 0.01
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
- risk 0.21cvss 4.3epss 0.00
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- risk 0.57cvss 8.8epss 0.00
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement…
- risk 0.18cvss 2.7epss 0.00
Webhook Authorization Header Returned in Plaintext via API
- risk 0.28cvss 4.3epss 0.00
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.59cvss 9.1epss 0.00
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
- risk 0.27cvss 5.3epss 0.00
Private Repository Existence Disclosure via go-get Meta Endpoint
- risk 0.18cvss 2.7epss 0.00
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- risk 0.21cvss 4.3epss 0.00
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- risk 0.59cvss 9.1epss 0.01
Public-only repository tokens can update private PR head branches
- risk 0.42cvss 6.5epss 0.00
Repository migration SSRF via multi-answer DNS allow-list bypass
- risk 0.41cvss 6.3epss 0.00
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- risk 0.37cvss 6.8epss 0.00
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
- risk 0.46cvss 8.1epss 0.01
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
- risk 0.49cvss 7.5epss 0.00
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
- risk 0.39cvss 7.1epss 0.00
Repository Visibility Manipulation via Git Push Options
- risk 0.42cvss 7.5epss 0.01
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests