CVE Vulnerability Database
Search and browse 390,098 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45489 | MEDIUM | 6.5 | 0.5% | Jul 3, 2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-45488 | MEDIUM | 5.9 | 0.3% | Jul 3, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-28744 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repos... |
| CVE-2026-28740 | HIGH | 7.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h... |
| CVE-2026-28737 | HIGH | 8.7 | 0.3% | Jul 3, 2026 | Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF ... |
| CVE-2026-28705 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as... |
| CVE-2026-28699 | HIGH | 8.1 | 0.6% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic ... |
| CVE-2026-27783 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints. |
| CVE-2026-27780 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin... |
| CVE-2026-27779 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp... |
| CVE-2026-27775 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo... |
| CVE-2026-27771 | HIGH | 8.2 | 40.7% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c... |
| CVE-2026-27761 | MEDIUM | 4.3 | 0.4% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope ... |
| CVE-2026-27660 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio... |
| CVE-2026-27657 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow a user to change another user's primary email address. |
| CVE-2026-26307 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve... |
| CVE-2026-26292 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ... |
| CVE-2026-26247 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi... |
| CVE-2026-26232 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during... |
| CVE-2026-26231 | HIGH | 8.5 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to... |
| CVE-2026-25782 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ... |
| CVE-2026-25779 | MEDIUM | 6.1 | 0.2% | Jul 3, 2026 | Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect... |
| CVE-2026-25718 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi... |
| CVE-2026-25714 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization... |
| CVE-2026-25712 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ... |
