2026 CVE Vulnerabilities

59,275 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25718CRITICAL9.1Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi...
CVE-2026-25714MEDIUM4.3Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization...
CVE-2026-25712HIGH7.5Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ...
CVE-2026-25038HIGH7.5Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20909MEDIUM5.3Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...
CVE-2026-20706CRITICAL9.1Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc...
CVE-2026-14611MEDIUM5.3A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ...
CVE-2026-14610MEDIUM5.3A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int...
CVE-2026-14609MEDIUM5.6A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue...
CVE-2026-14355MEDIUM5.3In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo...
CVE-2026-12481CRITICAL9.8A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser...
CVE-2026-14608MEDIUM4.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-14607MEDIUM5.5A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component...
CVE-2026-14606HIGH7.8A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ...
CVE-2026-14605HIGH7.8A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l...
CVE-2026-58379HIGH7.3A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem...
CVE-2026-14604MEDIUM6.3A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte...
CVE-2026-14631MEDIUM5.3webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now