Search
Search Results (376980 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28175 | 2 Wordpress, Wp-buy | 2 Wordpress, Visitor Traffic Real Time Statistics | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | ||||
| CVE-2026-28176 | 2 Booking Activities Team, Wordpress | 2 Booking Activities, Wordpress | 2026-08-13 | 8.8 High |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | ||||
| CVE-2026-28181 | 2 Acymailing Newsletter Team, Wordpress | 2 Acymailing Smtp Newsletter, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||||
| CVE-2026-28184 | 2 10web, Wordpress | 2 Form Maker By 10web, Wordpress | 2026-08-13 | 8.5 High |
| Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. | ||||
| CVE-2026-59765 | 2026-08-13 | N/A | ||
| SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | ||||
| CVE-2026-59763 | 2026-08-13 | N/A | ||
| Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||||
| CVE-2026-58511 | 2026-08-13 | N/A | ||
| Webhook Authorization Header Returned in Plaintext via API | ||||
| CVE-2026-58510 | 2026-08-13 | N/A | ||
| GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||||
| CVE-2026-58508 | 2026-08-13 | N/A | ||
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||||
| CVE-2026-58507 | 2026-08-13 | N/A | ||
| Private Repository Existence Disclosure via go-get Meta Endpoint | ||||
| CVE-2026-58445 | 2026-08-13 | N/A | ||
| Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||||
| CVE-2026-58444 | 2026-08-13 | N/A | ||
| Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||||
| CVE-2026-58443 | 2026-08-13 | N/A | ||
| Public-only repository tokens can update private PR head branches | ||||
| CVE-2026-58442 | 2026-08-13 | N/A | ||
| Repository migration SSRF via multi-answer DNS allow-list bypass | ||||
| CVE-2026-58441 | 2026-08-13 | N/A | ||
| SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | ||||
| CVE-2026-58440 | 2026-08-13 | N/A | ||
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | ||||
| CVE-2026-58439 | 2026-08-13 | N/A | ||
| Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | ||||
| CVE-2026-58438 | 2026-08-13 | N/A | ||
| Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | ||||
| CVE-2026-58437 | 2026-08-13 | N/A | ||
| Repository Visibility Manipulation via Git Push Options | ||||
| CVE-2026-58436 | 2026-08-13 | N/A | ||
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | ||||