Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48624
Total
3905
Critical
14425
High
14119
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56755 | MEDIUM | 6.2 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | Aug 13, 2026 |
| CVE-2026-56750 | UNKNOWN | — | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | Aug 13, 2026 |
| CVE-2026-56657 | MEDIUM | 6.2 | Gitea SSH Key Parser Denial of Service | Aug 13, 2026 |
| CVE-2026-56654 | UNKNOWN | — | Privilege Escalation via Access Token Scope Escalation in API | Aug 13, 2026 |
| CVE-2026-56443 | UNKNOWN | — | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | Aug 13, 2026 |
| CVE-2026-55987 | UNKNOWN | — | OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | Aug 13, 2026 |
| CVE-2026-55986 | UNKNOWN | — | Email Management API Bypasses ManageCredentials Feature Restrictions | Aug 13, 2026 |
| CVE-2026-55984 | UNKNOWN | — | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | Aug 13, 2026 |
| CVE-2026-55982 | UNKNOWN | — | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | Aug 13, 2026 |
| CVE-2026-55402 | UNKNOWN | — | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send … | Aug 13, 2026 |
| CVE-2026-54481 | UNKNOWN | — | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | Aug 13, 2026 |
| CVE-2026-50105 | UNKNOWN | — | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | Aug 13, 2026 |
| CVE-2026-42931 | MEDIUM | 6.5 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | Aug 13, 2026 |
| CVE-2026-24791 | HIGH | 8.1 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | Aug 13, 2026 |
| CVE-2026-24059 | UNKNOWN | — | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies … | Aug 13, 2026 |
| CVE-2026-23603 | UNKNOWN | — | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | Aug 13, 2026 |
| CVE-2026-13051 | UNKNOWN | — | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error … | Aug 13, 2026 |
| CVE-2026-13048 | HIGH | 8.2 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into … | Aug 13, 2026 |
| CVE-2022-4993 | CRITICAL | 9.1 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request … | Aug 13, 2026 |
| CVE-2026-73671 | MEDIUM | 6.1 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or … | Aug 13, 2026 |
| CVE-2026-73670 | HIGH | 7.2 | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM … | Aug 13, 2026 |
| CVE-2026-73576 | MEDIUM | 6.3 | In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number … | Aug 13, 2026 |
| CVE-2026-73575 | LOW | 3.1 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due … | Aug 13, 2026 |
| CVE-2026-73574 | LOW | 3.1 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu … | Aug 13, 2026 |
| CVE-2026-73573 | LOW | 3.1 | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages … | Aug 13, 2026 |