CVE search

369,371 results
CVE-2026-28737HIGHGitea 3D file viewer allows stored XSS through glTF extensionsRequiredEPSS 0.3%CVE-2026-28705MEDIUMGitea repository dumps write release assets using unsafe path namesEPSS 0.4%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2026-27783MEDIUMGitea issue-template APIs bypass repository unit authorizationEPSS 0.3%CVE-2026-27780CRITICALGitea pre-receive hook can miss branch-protection checks after scanner errorsEPSS 0.5%CVE-2026-27779HIGHGitea forwarded-proto handling allows public URL spoofingEPSS 0.4%CVE-2026-27775HIGHGitea pre-receive hook permission cache allows full repository write accessEPSS 0.5%CVE-2026-27771HIGHGitea Composer package source links use insufficient permission checksEPSS 40.7%CVE-2026-27761MEDIUMGitea repository feeds bypass API token scope enforcementEPSS 0.4%CVE-2026-27660HIGHGitea draft releases use insufficient permission checksEPSS 0.3%CVE-2026-27657HIGHGitea email settings allow changing another user's primary email addressEPSS 0.3%CVE-2026-26307HIGHGitea git grep search lacks a timeoutEPSS 0.5%CVE-2026-26292CRITICALGitea LFS mirror synchronization bypasses migration HTTP transport restrictionsEPSS 0.5%CVE-2026-26247CRITICALGitea OAuth2 PKCE S256 challenges are not enforced during token exchangeEPSS 0.4%CVE-2026-26232CRITICALGitea OAuth2 authorization codes lack expiry and reuse enforcementEPSS 0.4%CVE-2026-26231HIGHGitea maintainer-edit permissions allow unauthorized commits to readable repositoriesEPSS 0.3%CVE-2026-25782MEDIUMGitea tracked-time deletion can target entries from another issueEPSS 0.3%CVE-2026-25779MEDIUMGitea redirect handling permits open redirects through backslash pathsEPSS 0.2%CVE-2026-25718CRITICALGitea template repository generation mishandles symlinked pathsEPSS 0.4%CVE-2026-25714MEDIUMGitea user organization API bypasses public-only token filteringEPSS 0.3%