CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 12d ago | 7.1 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters. |
| Exploit 12d ago | 7.5 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata |
| Exploit 12d ago | 4.3 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads |
| 12d ago | 8.8 | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. |
| Exploit 12d ago | 2.7 | Webhook Authorization Header Returned in Plaintext via API |
| Exploit 12d ago | 4.3 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private |
| Exploit 12d ago | 9.1 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) |
| Exploit 12d ago | 5.3 | Private Repository Existence Disclosure via go-get Meta Endpoint |
| Exploit 12d ago | 2.7 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API |
| Exploit 12d ago | 4.3 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents |
| Exploit 12d ago | 9.1 | Public-only repository tokens can update private PR head branches |
| Exploit 12d ago | 6.5 | Repository migration SSRF via multi-answer DNS allow-list bypass |
| Exploit 12d ago | 6.3 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL |
| Exploit 12d ago | 6.8 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) |
| Exploit 12d ago | 8.1 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag |
| Exploit 12d ago | 7.5 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access |
| Exploit 12d ago | 7.1 | Repository Visibility Manipulation via Git Push Options |
| Exploit 12d ago | 7.5 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests |
| Exploit 12d ago | 5.4 | Gitea LFS Deploy-Key Privilege Escalation |
| Exploit 12d ago | 7.5 | Private Repository Metadata Remains Accessible After Access Revocation |
| Exploit 12d ago | 9.1 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting |
| Exploit 12d ago | 5.9 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea |
| Exploit 12d ago | 4.3 | Public-only API token restriction is not enforced on team API routes |
| Exploit 12d ago | 4.9 | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints |
| Exploit 12d ago | 6.5 | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) |
| Exploit 12d ago | 7.5 | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 |
| Exploit 12d ago | 4.3 | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) |
| Exploit 12d ago | 4.4 | Local File Inclusion via file:// URI in Migration Restore |
| Exploit 12d ago | 7.5 | REST API exposes organization membership of private organizations to public |
| Exploit 12d ago | 7.1 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) |