Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-52797 | HIGH | Patched | 8.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, tog… |
| CVE-2026-52798 | HIGH | Patched | 8.9 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content i… |
| CVE-2026-52799 | HIGH | Patched | 7.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view per… |
| CVE-2026-52800 | HIGH | Patched | 8.8 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim … |
| CVE-2026-52801 | HIGH | Patched | 8.1 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration fun… |
| CVE-2026-52802 | MEDIUM | Patched | 5.4 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass v… |
| CVE-2026-52804 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by… |
| CVE-2026-52805 | HIGH | Patched | 8.7 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The ap… |
| CVE-2026-52806 | CRITICAL | Patched | 9.9 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull req… |
| CVE-2026-52807 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts … |
| CVE-2026-52808 | HIGH | Patched | 7.1 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki… |
| CVE-2026-52809 | MEDIUM | Patched | 6.8 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), no… |
| CVE-2026-52810 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?servi… |
| CVE-2026-52811 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targ… |
| CVE-2026-52812 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid>) but per-repo authori… |
| CVE-2026-52813 | CRITICAL | Patched | 10.0 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under t… |
| CVE-2026-52814 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Denial of Service (DoS) att… |
| CVE-2026-52815 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpo… |
| CVE-2026-52816 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST /-/api/sanitize_ipynb allows arbitrary data: URIs w… |
| CVE-2026-7539 | NONE | — | 2026-06-24 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege an… | |
| CVE-2025-60468 | MEDIUM | Patched | 5.5 | 2026-06-24 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local).… |
| CVE-2026-10043 | HIGH | 7.8 | 2026-06-24 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… | |
| CVE-2026-10642 | MEDIUM | Patched | 4.6 | 2026-06-24 | The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven applica… |
| CVE-2026-2050 | HIGH | 7.8 | 2026-06-24 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta… | |
| CVE-2026-39893 | CRITICAL | Patched | 9.8 | 2026-06-24 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause with… |