CVE Vulnerability Database

Search and browse 390,098 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-25038HIGH7.5Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20909MEDIUM5.3Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...
CVE-2026-20706CRITICAL9.1Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc...
CVE-2026-14611MEDIUM5.3A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ...
CVE-2026-14610MEDIUM5.3A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int...
CVE-2026-14609MEDIUM5.6A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue...
CVE-2026-14355MEDIUM5.3In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo...
CVE-2026-12481CRITICAL9.8A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser...
CVE-2026-14608MEDIUM4.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-14607MEDIUM5.5A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component...
CVE-2026-14606HIGH7.8A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ...
CVE-2026-14605HIGH7.8A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l...
CVE-2026-58379HIGH7.3A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem...
CVE-2026-14604MEDIUM6.3A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte...
CVE-2026-14631MEDIUM5.3webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit...
CVE-2026-14620MEDIUM4.7webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a...
CVE-2026-14615LOW2.7A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service...
CVE-2026-14614MEDIUM5.4A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)...