Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2026-58439

23 дня назад

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-58438

23 дня назад

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58437

23 дня назад

Repository Visibility Manipulation via Git Push Options

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-58436

23 дня назад

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58435

23 дня назад

Gitea LFS Deploy-Key Privilege Escalation

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-58434

23 дня назад

Private Repository Metadata Remains Accessible After Access Revocation

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58433

23 дня назад

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-58432

23 дня назад

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-58431

23 дня назад

Public-only API token restriction is not enforced on team API routes

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-5842

5 месяцев назад

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-58429

23 дня назад

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-58428

23 дня назад

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-58427

23 дня назад

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58426

2 месяца назад

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2026-58425

23 дня назад

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-58424

2 месяца назад

Permanent Fork PR Workflow Approval Gate Bypass

CVSS3: 8.9
EPSS: Низкий
nvd логотип

CVE-2026-58423

2 месяца назад

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2026-58422

2 месяца назад

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-58421

2 месяца назад

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-58420

23 дня назад

Local File Inclusion via file:// URI in Migration Restore

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-58439

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

CVSS3: 8.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58438

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58437

Repository Visibility Manipulation via Git Push Options

CVSS3: 7.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58436

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

CVSS3: 5.4
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58434

Private Repository Metadata Remains Accessible After Access Revocation

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

CVSS3: 9.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

CVSS3: 5.9
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58431

Public-only API token restriction is not enforced on team API routes

CVSS3: 4.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-5842

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-58429

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

CVSS3: 4.9
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58428

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

CVSS3: 6.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58427

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58426

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

CVSS3: 9.6
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58425

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

CVSS3: 4.3
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-58424

Permanent Fork PR Workflow Approval Gate Bypass

CVSS3: 8.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58423

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

CVSS3: 7.7
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58422

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58421

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-58420

Local File Inclusion via file:// URI in Migration Restore

CVSS3: 4.4
0%
Низкий
23 дня назад

Уязвимостей на страницу