2026 CVE Vulnerabilities
59,275 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25718 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi... |
| CVE-2026-25714 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization... |
| CVE-2026-25712 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ... |
| CVE-2026-25038 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows unauthorized users to access labels of private organizations. |
| CVE-2026-24690 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. |
| CVE-2026-24451 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ... |
| CVE-2026-22874 | CRITICAL | 9.6 | 0.5% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. |
| CVE-2026-22555 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea... |
| CVE-2026-22547 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa... |
| CVE-2026-20909 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. |
| CVE-2026-20896 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour... |
| CVE-2026-20779 | HIGH | 7.1 | 0.5% | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac... |
| CVE-2026-20706 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc... |
| CVE-2026-14611 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ... |
| CVE-2026-14610 | MEDIUM | 5.3 | 0.1% | Jul 3, 2026 | A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int... |
| CVE-2026-14609 | MEDIUM | 5.6 | 0.3% | Jul 3, 2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue... |
| CVE-2026-14355 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo... |
| CVE-2026-12481 | CRITICAL | 9.8 | 0.4% | Jul 3, 2026 | A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser... |
| CVE-2026-14608 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-14607 | MEDIUM | 5.5 | 0.1% | Jul 3, 2026 | A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component... |
| CVE-2026-14606 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ... |
| CVE-2026-14605 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l... |
| CVE-2026-58379 | HIGH | 7.3 | 0.2% | Jul 3, 2026 | A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem... |
| CVE-2026-14604 | MEDIUM | 6.3 | 0.2% | Jul 3, 2026 | A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte... |
| CVE-2026-14631 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now