Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26379
Total
1954
Critical
7969
High
8218
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52804 | UNKNOWN | — | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an … | Jun 24, 2026 |
| CVE-2026-52802 | MEDIUM | 5.4 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, … | Jun 24, 2026 |
| CVE-2026-52801 | HIGH | 8.1 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New … | Jun 24, 2026 |
| CVE-2026-52800 | HIGH | 8.8 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If … | Jun 24, 2026 |
| CVE-2026-52799 | HIGH | 7.5 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view … | Jun 24, 2026 |
| CVE-2026-52798 | HIGH | 8.9 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content … | Jun 24, 2026 |
| CVE-2026-52797 | HIGH | 8.5 | Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to … | Jun 24, 2026 |
| CVE-2026-52796 | LOW | 3.5 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial … | Jun 24, 2026 |
| CVE-2026-52795 | MEDIUM | 4.3 | Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to, … | Jun 24, 2026 |
| CVE-2026-50129 | HIGH | 7.5 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception … | Jun 24, 2026 |
| CVE-2026-50128 | MEDIUM | 5.3 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit … | Jun 24, 2026 |
| CVE-2026-49278 | MEDIUM | 6.7 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by-id-1, … | Jun 24, 2026 |
| CVE-2026-49277 | UNKNOWN | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth … | Jun 24, 2026 |
| CVE-2026-47733 | MEDIUM | 4.4 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> … | Jun 24, 2026 |
| CVE-2026-47267 | HIGH | 8.3 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a … | Jun 24, 2026 |
| CVE-2026-46423 | UNKNOWN | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML service provider implementation … | Jun 24, 2026 |
| CVE-2026-45757 | UNKNOWN | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through … | Jun 24, 2026 |
| CVE-2026-45689 | CRITICAL | 9.1 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains … | Jun 24, 2026 |
| CVE-2026-45688 | CRITICAL | 9.1 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards … | Jun 24, 2026 |
| CVE-2026-45687 | HIGH | 8.5 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes … | Jun 24, 2026 |
| CVE-2026-45677 | UNKNOWN | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not … | Jun 24, 2026 |
| CVE-2026-33543 | UNKNOWN | — | FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. … | Jun 24, 2026 |
| CVE-2026-33235 | HIGH | 7.7 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block … | Jun 24, 2026 |
| CVE-2026-32315 | MEDIUM | 5.5 | motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf … | Jun 24, 2026 |
| CVE-2026-31978 | MEDIUM | 6.5 | motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to … | Jun 24, 2026 |