Export limit exceeded: 377388 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (377388 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65017 1 Apache 1 Airflow 2026-08-14 6.5 Medium
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option names and did not normalize team-prefixed sections before the sensitivity check (CWE-200). This is a distinct masker bypass from CVE-2026-48828 and CVE-2026-48892: deployments that upgraded to apache-airflow 3.3.0 to address those issues remain affected by this team-scoped variant. Users are advised to upgrade to apache-airflow 3.3.1 or later, which normalizes team-scoped sections before masking.
CVE-2026-59244 1 Apache 1 Airflow 2026-08-14 6.5 Medium
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
CVE-2026-59109 1 Zalktis Programmas 1 Zalktis 2026-08-14 8.8 High
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.
CVE-2026-58436 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.5 High
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 5.4 Medium
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.5 High
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58431 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 4.3 Medium
Public-only API token restriction is not enforced on team API routes
CVE-2026-58429 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 4.9 Medium
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 6.5 Medium
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.5 High
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58425 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 4.3 Medium
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58420 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 4.4 Medium
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58417 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.5 High
REST API exposes organization membership of private organizations to public
CVE-2026-58314 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.7 High
Two SSRF findings in Gitea 1.26.2
CVE-2026-57894 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 8.5 High
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-57886 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 5.9 Medium
Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-55984 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 2.7 Low
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-55982 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 9.1 Critical
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-54481 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.5 High
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
CVE-2026-59242 1 Apache 1 Airflow 2026-08-14 5.4 Medium
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.