VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,319 CVE recordsPage 427 of 1288 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-28744

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28740

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28737

Gitea Gitea Open Source Git Server

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-27780

Gitea Gitea Open Source Git Server

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27779

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27775

Gitea Gitea Open Source Git Server

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2026-27771

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

FIRST EPSS indicates an elevated probability of exploitation.