CVE Vulnerability Database
Search and browse 390,098 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25038 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows unauthorized users to access labels of private organizations. |
| CVE-2026-24690 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. |
| CVE-2026-24451 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ... |
| CVE-2026-22874 | CRITICAL | 9.6 | 0.5% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. |
| CVE-2026-22555 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea... |
| CVE-2026-22547 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa... |
| CVE-2026-20909 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. |
| CVE-2026-20896 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour... |
| CVE-2026-20779 | HIGH | 7.1 | 0.5% | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac... |
| CVE-2026-20706 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc... |
| CVE-2026-14611 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ... |
| CVE-2026-14610 | MEDIUM | 5.3 | 0.1% | Jul 3, 2026 | A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int... |
| CVE-2026-14609 | MEDIUM | 5.6 | 0.3% | Jul 3, 2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue... |
| CVE-2026-14355 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo... |
| CVE-2026-12481 | CRITICAL | 9.8 | 0.4% | Jul 3, 2026 | A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser... |
| CVE-2026-14608 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-14607 | MEDIUM | 5.5 | 0.1% | Jul 3, 2026 | A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component... |
| CVE-2026-14606 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ... |
| CVE-2026-14605 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l... |
| CVE-2026-58379 | HIGH | 7.3 | 0.2% | Jul 3, 2026 | A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem... |
| CVE-2026-14604 | MEDIUM | 6.3 | 0.2% | Jul 3, 2026 | A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte... |
| CVE-2026-14631 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit... |
| CVE-2026-14620 | MEDIUM | 4.7 | 0.1% | Jul 3, 2026 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a... |
| CVE-2026-14615 | LOW | 2.7 | 0.2% | Jul 3, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service... |
| CVE-2026-14614 | MEDIUM | 5.4 | 0.2% | Jul 3, 2026 | A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)... |
