Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,262
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 35,853 CVEs
CVE-2026-52809 MEDIUM - 6.8

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCodeLives. The token lifetime is baked into the token itself at generation time and is re-extracted fro...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52808 HIGH - 7.1

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints โ€” PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:owner/:repo/mirror-sync โ€” are gated by reqRepoWriter() rather than reqRepoAdmin(). The equivalent oper...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to &lt; etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text content of t...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52806 CRITICAL - 9.9

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase befor...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52805 HIGH - 8.7

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated u...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the ChangeCollaborationAccessMode function. This vulnerability is fixed in 0.14.3.

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52802 MEDIUM - 5.4

Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, allowing redirection to arbitrary external sites. All redirects in Gogs that are validated via the IsSameSite functio...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-56696 MEDIUM - 5.4

OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments....

Vendor: HKUDS
Product: OpenHarness
Published: Jun 23, 2026
Source: NVD
CVE-2026-56695 MEDIUM - 6.5

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and fil...

Vendor: HKUDS
Product: OpenHarness
Published: Jun 23, 2026
Source: NVD
CVE-2026-56694 MEDIUM - 5.4

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire messaging channels i...

Vendor: nanocoai
Product: nanoclaw
Published: Jun 23, 2026
Source: NVD
CVE-2026-56693 MEDIUM - 5.5

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container conf...

Vendor: nanocoai
Product: nanoclaw
Published: Jun 23, 2026
Source: NVD
CVE-2026-56692 MEDIUM - 5.5

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks wit...

Vendor: nanocoai
Product: nanoclaw
Published: Jun 23, 2026
Source: NVD
CVE-2026-56402 MEDIUM - 6.5

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payload...

Vendor: nanocoai
Product: nanoclaw
Published: Jun 23, 2026
Source: NVD
CVE-2026-52673 MEDIUM - 6.5

SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component

Published: Jun 23, 2026
Source: NVD

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.

Vendor: Pegasystems
Product: Pega Infinity
Published: Jun 23, 2026
Source: NVD
CVE-2025-55639 MEDIUM - 6.5

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

Published: Jun 23, 2026
Source: NVD

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

Vendor: HCLSoftware
Product: Connections
Published: Jun 23, 2026
Source: NVD
CVE-2026-56815 HIGH - 7.4

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

Vendor: rasta-mouse
Product: pwnlift
Published: Jun 23, 2026
Source: NVD
CVE-2026-35019 HIGH - 8.1

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge ...

Vendor: NetComm Wireless Pty Ltd
Product: NF20MESH
Published: Jun 23, 2026
Source: NVD
CVE-2026-35018 HIGH - 8.8

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAc...

Vendor: NetComm Wireless Pty Ltd
Product: NF20MESH
Published: Jun 23, 2026
Source: NVD