|
441
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCo…
New
|
CWE-324 CWE-613
Use of a Key Past its Expiration Date Insufficient Session Expiration
|
CVE-2026-52809
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
442
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially craft…
New
|
CWE-77
Command Injection
|
CVE-2026-52806
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
443
|
8.7 |
HIGH
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only th…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-52805
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
444
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the ChangeCol…
New
|
CWE-193
Off-by-one Error
|
CVE-2026-52804
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
445
|
8.8 |
HIGH
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owne…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-52800
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
446
|
6.8 |
MEDIUM
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrit…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-50573
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
447
|
6.8 |
MEDIUM
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker c…
New
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-50021
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
448
|
8.8 |
HIGH
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses th…
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-50016
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
449
|
6.4 |
MEDIUM
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git depend…
New
|
CWE-88
Argument Injection
|
CVE-2026-50014
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
450
|
6.7 |
MEDIUM
Network
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://devel…
New
|
CWE-285
Improper Authorization
|
CVE-2026-49278
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|