🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-96580 Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pu... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-96404 When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, s... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-96400 With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit res... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-96399 A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea ren... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-95112 When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" ... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-95106 Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views reso... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-94205 Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. F... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-89430 Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchroniz... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79960 When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline eva... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79818 A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication c... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79817 A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation cou... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79816 A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79815 A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary co... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79814 An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their u... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79813 A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79812 A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authe... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79811 A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to con... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79810 Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated rem... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79809 An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability a... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79808 A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local us... | HIGH | ????? | ????? | NVD | 1 day ago |