2026 CVE Vulnerabilities
47,535 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27779 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp... |
| CVE-2026-27775 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo... |
| CVE-2026-27771 | HIGH | 8.2 | 40.7% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c... |
| CVE-2026-27660 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio... |
| CVE-2026-27657 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow a user to change another user's primary email address. |
| CVE-2026-26307 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve... |
| CVE-2026-26231 | HIGH | 8.5 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to... |
| CVE-2026-25712 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ... |
| CVE-2026-25038 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows unauthorized users to access labels of private organizations. |
| CVE-2026-24690 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. |
| CVE-2026-24451 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ... |
| CVE-2026-22555 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea... |
| CVE-2026-20779 | HIGH | 7.1 | 0.5% | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac... |
| CVE-2026-14606 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ... |
| CVE-2026-14605 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l... |
| CVE-2026-58379 | HIGH | 7.3 | 0.2% | Jul 3, 2026 | A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem... |
| CVE-2026-53478 | HIGH | 7.2 | 1.2% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-49815 | HIGH | 7.2 | 1.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-49814 | HIGH | 7.2 | 1.2% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-14460 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Ar... |
| CVE-2026-14459 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Softw... |
| CVE-2026-13341 | HIGH | 7.4 | 0.3% | Jul 3, 2026 | A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow... |
| CVE-2026-10055 | HIGH | 8.5 | 0.3% | Jul 3, 2026 | In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from... |
| CVE-2026-10054 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc... |
| CVE-2026-47896 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now