Export limit exceeded: 377137 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 377137 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (377137 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19382 1 Almico 1 Speedfan 2026-08-13 2.3 Low
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-52640 2026-08-13 4.7 Medium
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.
CVE-2026-57894 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-58314 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Two SSRF findings in Gitea 1.26.2
CVE-2026-58420 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58442 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58444 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-59765 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-67614 1 Usmannasir 1 Cyberpanel 2026-08-13 9.8 Critical
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
CVE-2026-58417 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
REST API exposes organization membership of private organizations to public
CVE-2026-58425 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58428 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58429 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58431 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Public-only API token restriction is not enforced on team API routes
CVE-2026-58432 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58433 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58435 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58436 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58438 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58440 1 Gitea 1 Gitea Open Source Git Server 2026-08-13 N/A
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)