Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 3

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API GiteaGitea Open Source Git Server--2026-08-13 16:44:43 Deep Dive
CVE-2026-56657 Gitea SSH Key Parser Denial of Service GiteaGitea Open Source Git Server--2026-08-13 16:44:43 Deep Dive
CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) GiteaGitea Open Source Git Server--2026-08-13 16:44:42 Deep Dive
CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 GiteaGitea Open Source Git Server--2026-08-13 16:44:42 Deep Dive
CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions GiteaGitea Open Source Git Server--2026-08-13 16:44:42 Deep Dive
CVE-2026-55984 Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service GiteaGitea Open Source Git Server--2026-08-13 16:44:41 Deep Dive
CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) GiteaGitea Open Source Git Server--2026-08-13 16:44:40 Deep Dive
CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes GiteaGitea Open Source Git Server--2026-08-13 16:44:40 Deep Dive
CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint GiteaGitea Open Source Git Server--2026-08-13 16:44:39 Deep Dive
CVE-2026-50105 RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) GiteaGitea Open Source Git Server--2026-08-13 16:44:39 Deep Dive
CVE-2026-23603 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim GiteaGitea Open Source Git Server--2026-08-13 16:44:38 Deep Dive
CVE-2026-59109 Zalktis: SQL injection via partner-controlled fields in imported e-invoices Zalktis Programmas (SIA "Zalktis Programmas")Zalktis High 8.8 2026-08-13 16:40:02 Deep Dive
CVE-2026-73266 Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join Red HatMulticluster Engine for Kubernetes High 7.1 2026-08-13 16:36:45 Deep Dive
CVE-2026-13051 Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template ----2026-08-13 16:28:50 Deep Dive
CVE-2026-13048 Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename ----2026-08-13 16:28:26 Deep Dive
CVE-2022-4993 HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template ----2026-08-13 16:27:47 Deep Dive
CVE-2026-55402 Secure Access servers <14.57越界读取导致DoS Absolute SecuritySecure Access High 8.7 2026-08-13 16:16:22 Deep Dive
CVE-2026-55401 Secure Access<14.57空指针引用致负载子系统崩溃 Absolute SecuritySecure Access Medium 6.9 2026-08-13 16:11:09 Deep Dive
CVE-2026-55400 Secure Access <14.57整数下溢致拒绝服务 Absolute SecuritySecure Access Medium 6.0 2026-08-13 16:05:10 Deep Dive
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build WPManageNinjaFluent Forms Pro Critical 9.8 2026-08-13 16:01:20 Deep Dive