CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-58422

    Last Modified: 6 Jul 2026

    Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58421

    Last Modified: 6 Jul 2026

    Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58419

    Last Modified: 6 Jul 2026

    Notification API leaks private issue metadata after access revocation

    Published: 3 Jul 2026
    6.5
    Medium

    CVE-2026-58418

    Last Modified: 6 Jul 2026

    SSRF via HTTP Redirect in Repository Migration

    Published: 3 Jul 2026
    1.9
    Low

    CVE-2026-14610

    Last Modified: 6 Jul 2026

    A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.

    Published: 3 Jul 2026
    9.8
    Critical

    CVE-2026-12481

    Last Modified: 6 Jul 2026

    A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), bypassing the guard and allowing attacker-controlled `marshal` bytecode to be deserialized. Affected call sites include `keras.layers.deserialize(config)`, `keras.models.clone_model(model)`, and any direct invocation of `Lambda.from_config(config)` without an enclosing `SafeModeScope(True)`. This vulnerability can be exploited to achieve arbitrary OS-level code execution in the context of the server or user process.

    Published: 3 Jul 2026
    6.1
    Medium

    CVE-2026-58291

    Last Modified: 6 Jul 2026

    Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

    Published: 3 Jul 2026
    6.5
    Medium

    CVE-2026-45489

    Last Modified: 12 Jul 2026

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 3 Jul 2026
    4.3
    Medium

    CVE-2026-58597

    Last Modified: 6 Jul 2026

    Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    5.4
    Medium

    CVE-2026-58524

    Last Modified: 6 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    6.2
    Medium

    CVE-2026-58300

    Last Modified: 6 Jul 2026

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

    Published: 3 Jul 2026
    7.2
    High

    CVE-2026-58298

    Last Modified: 7 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    7.1
    High

    CVE-2026-58297

    Last Modified: 6 Jul 2026

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

    Published: 3 Jul 2026
    7.1
    High

    CVE-2026-58296

    Last Modified: 6 Jul 2026

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

    Published: 3 Jul 2026
    8.3
    High

    CVE-2026-58295

    Last Modified: 6 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58294

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.1
    High

    CVE-2026-58293

    Last Modified: 6 Jul 2026

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58292

    Last Modified: 6 Jul 2026

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58290

    Last Modified: 7 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    9
    Critical

    CVE-2026-58289

    Last Modified: 6 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.3
    High

    CVE-2026-58288

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.1
    High

    CVE-2026-58286

    Last Modified: 7 Jul 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    8.3
    High

    CVE-2026-58285

    Last Modified: 6 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.3
    High

    CVE-2026-58284

    Last Modified: 6 Jul 2026

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    5.4
    Medium

    CVE-2026-58278

    Last Modified: 6 Jul 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58276

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.4
    High

    CVE-2026-57991

    Last Modified: 6 Jul 2026

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-57986

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.8
    High

    CVE-2026-57981

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.1
    High

    CVE-2026-57977

    Last Modified: 6 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    8.8
    High

    CVE-2026-57974

    Last Modified: 7 Jul 2026

    Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    5.4
    Medium

    CVE-2026-45488

    Last Modified: 7 Jul 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    6.8
    Medium

    CVE-2026-58522

    Last Modified: 6 Jul 2026

    Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-58299

    Last Modified: 6 Jul 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.3
    High

    CVE-2026-58287

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.1
    High

    CVE-2026-58283

    Last Modified: 6 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    8.1
    High

    CVE-2026-58282

    Last Modified: 6 Jul 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    6.5
    Medium

    CVE-2026-56646

    Last Modified: 6 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    7.4
    High

    CVE-2026-57993

    Last Modified: 6 Jul 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-57992

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.1
    High

    CVE-2026-57988

    Last Modified: 6 Jul 2026

    Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    6.5
    Medium

    CVE-2026-57987

    Last Modified: 6 Jul 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Jul 2026
    7.6
    High

    CVE-2026-57985

    Last Modified: 6 Jul 2026

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-57984

    Last Modified: 6 Jul 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.7
    High

    CVE-2026-57983

    Last Modified: 6 Jul 2026

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

    Published: 3 Jul 2026
    7.5
    High

    CVE-2026-57975

    Last Modified: 6 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    8.8
    High

    CVE-2026-56645

    Last Modified: 6 Jul 2026

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Jul 2026
    4.2
    Medium

    CVE-2026-55945

    Last Modified: 6 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

    Published: 3 Jul 2026
    8.1
    High

    CVE-2026-28744

    Last Modified: 6 Jul 2026

    Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

    Published: 3 Jul 2026
    7.1
    High

    CVE-2026-28740

    Last Modified: 7 Jul 2026

    Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

    Published: 3 Jul 2026