Products: 3
    Vulnerabilities: 143
    Known Exploited: 1
    30
    Critical Level Threats
    51
    High Level Threats
    55
    Medium Level Threats
    7
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-60004

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

    Last Modified: Aug 27, 2026
    Published: Aug 26, 2026

    CVE-2026-24059

    Gitea runner registration-token GET endpoint performs a write under a read-only token scope

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-24791

    Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

    Last Modified: Aug 13, 2026
    Published: Aug 13, 2026

    CVE-2026-59765

    SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-59763

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

    Last Modified: Aug 13, 2026
    Published: Aug 13, 2026
    Items Per Page
    Gitea Vulnerabilities & Security CVEs | CVE-DB