Common Vulnerabilities and Exposures (CVE)

CVE-2026-101027

Oct 7, 2026 11:37:44 UTC

When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS...

CVE-2026-96400

Oct 7, 2026 11:35:27 UTC

With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = fal...

CVE-2026-89182

Oct 7, 2026 11:34:42 UTC

With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories c...

CVE-2026-93026

Oct 7, 2026 11:31:29 UTC

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.

CVE-2026-58069

Oct 7, 2026 11:31:00 UTC

This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.

CVE-2026-83742

Oct 7, 2026 11:30:28 UTC

Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by se...

CVE-2026-59346

Oct 7, 2026 11:29:55 UTC

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. A...

CVE-2026-59347

Oct 7, 2026 11:29:34 UTC

VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX proce...

CVE-2026-83540

Oct 7, 2026 11:29:08 UTC

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in use...

CVE-2026-16516

Oct 7, 2026 11:17:14 UTC

wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via...

CVE-2026-106033

Oct 7, 2026 11:11:31 UTC

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next quer...

CVE-2026-42713

Oct 7, 2026 10:57:48 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from...

CVE-2026-42714

Oct 7, 2026 10:56:56 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce...

CVE-2026-92533

Oct 7, 2026 10:48:59 UTC

Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to acces...

CVE-2026-92532

Oct 7, 2026 10:48:48 UTC

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web inter...