VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,309 CVE recordsPage 426 of 1288 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-28744

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28740

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28737

Gitea Gitea Open Source Git Server

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-27780

Gitea Gitea Open Source Git Server

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27779

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

The CVSS severity warrants an early asset and exposure review.