| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58435 | Med | 0.35 | 5.4 | 0.00 | Aug 13, 2026 | Gitea LFS Deploy-Key Privilege Escalation | ||
| CVE-2026-58434 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private Repository Metadata Remains Accessible After Access Revocation | ||
| CVE-2026-58433 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | ||
| CVE-2026-58432 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | ||
| CVE-2026-58431 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | Public-only API token restriction is not enforced on team API routes | ||
| CVE-2026-58429 | Med | 0.25 | 4.9 | 0.00 | Aug 13, 2026 | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||
| CVE-2026-58428 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | ||
| CVE-2026-58427 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | ||
| CVE-2026-58425 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | ||
| CVE-2026-58420 | Med | 0.29 | 4.4 | 0.00 | Aug 13, 2026 | Local File Inclusion via file:// URI in Migration Restore | ||
| CVE-2026-58417 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | REST API exposes organization membership of private organizations to public | ||
| CVE-2026-58416 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||
| CVE-2026-58314 | Hig | 0.43 | 7.7 | 0.00 | Aug 13, 2026 | Two SSRF findings in Gitea 1.26.2 | ||
| CVE-2026-57897 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | ||
| CVE-2026-57894 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | ||
| CVE-2026-57886 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Cross-repository issue/comment attachment re-linking can expose private attachment content | ||
| CVE-2026-56755 | Med | 0.33 | 6.2 | 0.00 | Aug 13, 2026 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | ||
| CVE-2026-56750 | Cri | 0.52 | 9.1 | 0.00 | Aug 13, 2026 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | ||
| CVE-2026-56657 | Med | 0.33 | 6.2 | 0.00 | Aug 13, 2026 | Gitea SSH Key Parser Denial of Service | ||
| CVE-2026-56654 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | Privilege Escalation via Access Token Scope Escalation in API | ||
| CVE-2026-56443 | Cri | 0.55 | 9.6 | 0.01 | Aug 13, 2026 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | ||
| CVE-2026-55987 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | ||
| CVE-2026-55986 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | Email Management API Bypasses ManageCredentials Feature Restrictions | ||
| CVE-2026-55984 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | ||
| CVE-2026-55982 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | ||
| CVE-2026-55402 | Med | 0.38 | 5.9 | 0.00 | Aug 13, 2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. | ||
| CVE-2026-54481 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | ||
| CVE-2026-50105 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | ||
| CVE-2026-42931 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2026 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | ||
| CVE-2026-24791 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | ||
| CVE-2026-24059 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked… | ||
| CVE-2026-23603 | Low | 0.13 | 3.1 | 0.00 | Aug 13, 2026 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | ||
| CVE-2026-13051 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the… | ||
| CVE-2026-13048 | Hig | 0.53 | 8.2 | 0.01 | Aug 13, 2026 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending… | ||
| CVE-2022-4993 | Cri | 0.52 | 9.1 | 0.01 | Aug 13, 2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first… | ||
| CVE-2026-73671 | Med | 0.40 | 6.1 | 0.00 | Aug 13, 2026 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or… | ||
| CVE-2026-73670 | Hig | 0.47 | 7.2 | 0.01 | Aug 13, 2026 | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform… | ||
| CVE-2026-73576 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who… | ||
| CVE-2026-73575 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by… | ||
| CVE-2026-73574 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially… | ||
| CVE-2026-73573 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path… | ||
| CVE-2026-73572 | Med | 0.40 | 6.1 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a… | ||
| CVE-2026-73571 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2026 | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send… | ||
| CVE-2026-73570 | Hig | 0.70 | 8.9 | 0.72 | KEV | Aug 13, 2026 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an… | |
| CVE-2026-73559 | Med | 0.35 | 6.5 | 0.01 | Aug 13, 2026 | vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in… | ||
| CVE-2026-73533 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor… | ||
| CVE-2026-73532 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added… | ||
| CVE-2026-73515 | Hig | 0.53 | 8.1 | 0.01 | Aug 13, 2026 | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails… | ||
| CVE-2026-73514 | Hig | 0.50 | 8.8 | 0.01 | Aug 13, 2026 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by… | ||
| CVE-2026-55401 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2026 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer… |
- risk 0.35cvss 5.4epss 0.00
Gitea LFS Deploy-Key Privilege Escalation
- risk 0.42cvss 7.5epss 0.00
Private Repository Metadata Remains Accessible After Access Revocation
- risk 0.59cvss 9.1epss 0.01
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
- risk 0.31cvss 5.9epss 0.00
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
- risk 0.28cvss 4.3epss 0.00
Public-only API token restriction is not enforced on team API routes
- risk 0.25cvss 4.9epss 0.00
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- risk 0.35cvss 6.5epss 0.00
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- risk 0.42cvss 7.5epss 0.00
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
- risk 0.21cvss 4.3epss 0.00
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
- risk 0.29cvss 4.4epss 0.00
Local File Inclusion via file:// URI in Migration Restore
- risk 0.42cvss 7.5epss 0.00
REST API exposes organization membership of private organizations to public
- risk 0.39cvss 7.1epss 0.00
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- risk 0.43cvss 7.7epss 0.00
Two SSRF findings in Gitea 1.26.2
- risk 0.35cvss 6.5epss 0.00
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
- risk 0.55cvss 8.5epss 0.00
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
- risk 0.31cvss 5.9epss 0.00
Cross-repository issue/comment attachment re-linking can expose private attachment content
- risk 0.33cvss 6.2epss 0.00
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
- risk 0.52cvss 9.1epss 0.00
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
- risk 0.33cvss 6.2epss 0.00
Gitea SSH Key Parser Denial of Service
- risk 0.57cvss 9.8epss 0.01
Privilege Escalation via Access Token Scope Escalation in API
- risk 0.55cvss 9.6epss 0.01
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
- risk 0.53cvss 8.1epss 0.00
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
- risk 0.28cvss 5.4epss 0.00
Email Management API Bypasses ManageCredentials Feature Restrictions
- risk 0.18cvss 2.7epss 0.00
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
- risk 0.59cvss 9.1epss 0.01
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- risk 0.38cvss 5.9epss 0.00
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
- risk 0.49cvss 7.5epss 0.00
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
- risk 0.28cvss 4.3epss 0.00
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- risk 0.42cvss 6.5epss 0.01
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
- risk 0.46cvss 8.1epss 0.00
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
- risk 0.35cvss 6.5epss 0.00
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked…
- risk 0.13cvss 3.1epss 0.00
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- risk 0.59cvss 9.1epss 0.01
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the…
- risk 0.53cvss 8.2epss 0.01
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending…
- risk 0.52cvss 9.1epss 0.01
HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first…
- risk 0.40cvss 6.1epss 0.00
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or…
- risk 0.47cvss 7.2epss 0.01
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform…
- risk 0.41cvss 6.3epss 0.00
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who…
- risk 0.20cvss 3.1epss 0.00
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by…
- risk 0.20cvss 3.1epss 0.00
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially…
- risk 0.20cvss 3.1epss 0.00
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path…
- risk 0.40cvss 6.1epss 0.00
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a…
- risk 0.20cvss 3.1epss 0.00
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send…
- risk 0.70cvss 8.9epss 0.72
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an…
- risk 0.35cvss 6.5epss 0.01
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in…
- risk 0.64cvss 9.8epss 0.01
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor…
- risk 0.64cvss 9.8epss 0.01
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added…
- risk 0.53cvss 8.1epss 0.01
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails…
- risk 0.50cvss 8.8epss 0.01
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by…
- risk 0.34cvss 5.3epss 0.00
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer…