Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-12908 NONE — 2026-08-13 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be…
CVE-2026-12236 MEDIUM 6.5 2026-08-13 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server du…
CVE-2024-58374 HIGH 7.5 2026-08-13 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected …
CVE-2019-25765 HIGH 7.5 2026-08-13 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id p…
CVE-2026-73266 HIGH 7.1 2026-08-13 A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim…
CVE-2026-59765 HIGH 7.5 2026-08-13 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-59763 MEDIUM 4.3 2026-08-13 Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-59109 HIGH Patched 8.8 2026-08-13 SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEP…
CVE-2026-58511 LOW 2.7 2026-08-13 Webhook Authorization Header Returned in Plaintext via API
CVE-2026-58510 MEDIUM 4.3 2026-08-13 GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-58508 CRITICAL 9.1 2026-08-13 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58507 MEDIUM 5.3 2026-08-13 Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58445 LOW 2.7 2026-08-13 Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58444 MEDIUM 4.3 2026-08-13 Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58443 CRITICAL 9.1 2026-08-13 Public-only repository tokens can update private PR head branches
CVE-2026-58442 MEDIUM 6.5 2026-08-13 Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441 MEDIUM 6.3 2026-08-13 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440 MEDIUM 6.8 2026-08-13 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in…
CVE-2026-58439 HIGH 8.1 2026-08-13 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438 HIGH 7.5 2026-08-13 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58437 HIGH 7.1 2026-08-13 Repository Visibility Manipulation via Git Push Options
CVE-2026-58436 HIGH 7.5 2026-08-13 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435 MEDIUM 5.4 2026-08-13 Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434 HIGH 7.5 2026-08-13 Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58433 CRITICAL 9.1 2026-08-13 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting