7.2

CVSS4.0

CVE-2026-24135 - Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated user with write access to a repository's wiki to delete arbitrary files on the server by manipulating …

📅 Published: Feb. 6, 2026, 5:47 p.m. 🔄 Last Modified: April 17, 2026, 10:45 p.m.

6.5

CVSS3.1

CVE-2026-23633 - Gogs has arbitrary file read/write via path traversal in Git hook editing

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.

📅 Published: Feb. 6, 2026, 5:46 p.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

5.3

CVSS4.0

CVE-2026-24903 - OrcaStatLLM Researcher Stored Cross-Site Scripting (XSS) via Log Message Injection in Session Page

OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through mali…

📅 Published: Feb. 6, 2026, 5:46 p.m. 🔄 Last Modified: April 17, 2026, 10:45 p.m.

9.4

CVSS3.1

CVE-2026-1709 - Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missin…

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing a…

📅 Published: Feb. 6, 2026, 5:45 p.m. 🔄 Last Modified: April 16, 2026, 5:30 p.m.

6.5

CVSS3.1

CVE-2026-23632 - Gogs user can update repository content with read-only permission

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permission only via repoAssignment(). After passing the permission check, PutContents() invokes UpdateRepoFil…

📅 Published: Feb. 6, 2026, 5:43 p.m. 🔄 Last Modified: April 17, 2026, 10:45 p.m.

6.5

CVSS3.1

CVE-2026-22592 - Gogs is Vulnerable to Denial of Service

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause the application to crash. This issue has been patched in versions 0.13.4 and 0.14.0+dev.

📅 Published: Feb. 6, 2026, 5:42 p.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.

7.7

CVSS4.0

CVE-2025-64175 - Gogs Vulnerable to 2FA Bypass via Recovery Code

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a victim’s username and password, they can use any unused recovery code (e.g., from their own account) to…

📅 Published: Feb. 6, 2026, 5:41 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

6.9

CVSS4.0

CVE-2026-2060 - code-projects Simple Blood Donor Management System editcampaignform.php sql injection

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the a…

📅 Published: Feb. 6, 2026, 5:32 p.m. 🔄 Last Modified: April 17, 2026, 10:45 p.m.

5.3

CVSS3.1

CVE-2026-1769 - Stored XSS on Xerox CentreWare Web 7.0.6

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

📅 Published: Feb. 6, 2026, 5:19 p.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

6.9

CVSS4.0

CVE-2026-2059 - SourceCodester Medical Center Portal Management System emp_edit1.php sql injection

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the publi…

📅 Published: Feb. 6, 2026, 5:02 p.m. 🔄 Last Modified: April 17, 2026, 10:45 p.m.
Total resulsts: 349182
Page 1770 of 34,919
« previous page » next page
Filters