Search Results (6687 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65773 1 Microsoft 16 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 13 more 2026-08-13 7.8 High
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-59763 2026-08-13 N/A
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58508 2026-08-13 N/A
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58507 2026-08-13 N/A
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58440 2026-08-13 N/A
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58439 2026-08-13 N/A
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58437 2026-08-13 N/A
Repository Visibility Manipulation via Git Push Options
CVE-2026-58429 2026-08-13 N/A
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58420 2026-08-13 N/A
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58417 2026-08-13 N/A
REST API exposes organization membership of private organizations to public
CVE-2026-56755 2026-08-13 N/A
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-56750 2026-08-13 N/A
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-56657 2026-08-13 N/A
Gitea SSH Key Parser Denial of Service
CVE-2026-56654 2026-08-13 N/A
Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-55986 2026-08-13 N/A
Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-55984 2026-08-13 N/A
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-18750 1 Cert 1 Vince 2026-08-13 5.3 Medium
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.
CVE-2026-18749 1 Cert 1 Vince 2026-08-13 9.8 Critical
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.
CVE-2026-18744 1 Cert 1 Vince 2026-08-13 6.5 Medium
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant.
CVE-2026-14857 2026-08-13 4.3 Medium
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to its backers, allowing any authenticated users such as Subscribers to alter other users' campaigns.