| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-56654 | Privilege Escalation via Access Token Scope Escalation in API | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:43 | Deep Dive |
| CVE-2026-56657 | Gitea SSH Key Parser Denial of Service | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:43 | Deep Dive |
| CVE-2026-55987 | OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-56443 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-55986 | Email Management API Bypasses ManageCredentials Feature Restrictions | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-55984 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:41 | Deep Dive |
| CVE-2026-54481 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:40 | Deep Dive |
| CVE-2026-55982 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:40 | Deep Dive |
| CVE-2026-42931 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:39 | Deep Dive |
| CVE-2026-50105 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:39 | Deep Dive |
| CVE-2026-23603 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:38 | Deep Dive |
| CVE-2026-59109 | Zalktis: SQL injection via partner-controlled fields in imported e-invoices | Zalktis Programmas (SIA "Zalktis Programmas") | Zalktis | High | 8.8 | 2026-08-13 16:40:02 | Deep Dive |
| CVE-2026-73266 | Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join | Red Hat | Multicluster Engine for Kubernetes | High | 7.1 | 2026-08-13 16:36:45 | Deep Dive |
| CVE-2026-13051 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template | - | - | - | - | 2026-08-13 16:28:50 | Deep Dive |
| CVE-2026-13048 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename | - | - | - | - | 2026-08-13 16:28:26 | Deep Dive |
| CVE-2022-4993 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template | - | - | - | - | 2026-08-13 16:27:47 | Deep Dive |
| CVE-2026-55402 | Secure Access servers <14.57越界读取导致DoS | Absolute Security | Secure Access | High | 8.7 | 2026-08-13 16:16:22 | Deep Dive |
| CVE-2026-55401 | Secure Access<14.57空指针引用致负载子系统崩溃 | Absolute Security | Secure Access | Medium | 6.9 | 2026-08-13 16:11:09 | Deep Dive |
| CVE-2026-55400 | Secure Access <14.57整数下溢致拒绝服务 | Absolute Security | Secure Access | Medium | 6.0 | 2026-08-13 16:05:10 | Deep Dive |
| CVE-2026-73532 | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build | WPManageNinja | Fluent Forms Pro | Critical | 9.8 | 2026-08-13 16:01:20 | Deep Dive |