5
CVE-2025-68944 - gitea: Gitea: Access control bypass in package registries
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
5.3
CVE-2025-68943 - gitea: Gitea: Information disclosure of user login times via sort order
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
5.3
CVE-2025-15098 - YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery
A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/header/body can lead to server-side request forgery. The attack mayโฆ
5.4
CVE-2025-68942 - gitea: Gitea: Cross-Site Scripting (XSS) vulnerability via search input
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
6.9
CVE-2025-15097 - Alteryx Server status improper authentication
A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipulation results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrโฆ
4.9
CVE-2025-68941 - gitea: Gitea: Unauthorized access to private resources via public-scoped API tokens
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
3.1
CVE-2025-68940 - gitea: Gitea: Unauthorized branch deletion due to inadequate permission enforcement
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
8.2
CVE-2025-68939 - gitea: attachments can be renamed to forbidden file extensions via the attachment API
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
5.1
CVE-2025-15095 - postmanlabs httpbin core.py cross site scripting
A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. โฆ
5.3
CVE-2025-15094 - sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting
A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can โฆ