İçeriğe atla
Noroxi

Gitea kayıtları

gitea üreticisine ait 54 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %1,9
Silahlaştırılmış
3 · %5,6
Pre-auth RCE
4
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
-1 gün

Tüm kayıtlar

54 kayıt
  • CVE-2026-60004
    76Bu hafta

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %24

    gitea · gitea26 Ağu 2026

  • CVE-2020-14144
    57Planlayın

    The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the do

    YüksekCVSS 7,2SilahlaştırılmışEPSS %95

    gitea · gitea16 Eki 2020

  • CVE-2022-30781
    56Planlayın

    Gitea before 1.16.7 does not escape git fetch remote.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %88

    gitea · gitea16 May 2022

  • CVE-2019-11229
    51Planlayın

    models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

    YüksekCVSS 8,8Kavram kanıtıEPSS %55

    gitea · gitea15 Nis 2019

  • CVE-2024-6886
    50Planlayın

    Inproper Sanitation of field leading to stored XSS

    KritikCVSS 10,0Kavram kanıtıEPSS %33

    gitea · gitea open source git server6 Ağu 2024

  • CVE-2022-1058
    40Planlayın

    Open Redirect on login in go-gitea/gitea

    OrtaCVSS 6,1Kavram kanıtıEPSS %53

    gitea · gitea24 Mar 2022

  • CVE-2018-18926
    40Planlayın

    Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.

    KritikCVSS 9,8İstismar yokEPSS %3

    gitea · gitea4 Kas 2018

  • CVE-2021-45327
    40Planlayın

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.

    KritikCVSS 9,8İstismar yokEPSS %2

    gitea · gitea8 Şub 2022

  • CVE-2019-11576
    40Planlayın

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment.

    KritikCVSS 9,8İstismar yokEPSS %2

    gitea · gitea27 Nis 2019

  • CVE-2020-28991
    40Planlayın

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (

    KritikCVSS 9,8İstismar yokEPSS %2

    gitea · gitea23 Kas 2020

  • CVE-2021-45330
    39İzleyin

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t

    KritikCVSS 9,8İstismar yokEPSS %1

    gitea · gitea9 Şub 2022

  • CVE-2021-45331
    39İzleyin

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges.

    KritikCVSS 9,8İstismar yokEPSS %1

    gitea · gitea9 Şub 2022

  • CVE-2022-42968
    39İzleyin

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend.

    KritikCVSS 9,8İstismar yokEPSS %1

    gitea · gitea16 Eki 2022

  • CVE-2026-20912
    36İzleyin

    Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure

    KritikCVSS 9,1İstismar yokEPSS %0

    gitea · gitea22 Oca 2026

  • CVE-2026-20897
    36İzleyin

    Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)

    KritikCVSS 9,1İstismar yokEPSS %0

    gitea · gitea22 Oca 2026

  • CVE-2026-20750
    36İzleyin

    Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)

    KritikCVSS 9,1İstismar yokEPSS %0

    gitea · gitea22 Oca 2026

  • CVE-2018-15192
    35İzleyin

    An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

    YüksekCVSS 8,6İstismar yokEPSS %2

    gitea · gitea7 Ağu 2018

  • CVE-2021-45326
    35İzleyin

    Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state alte

    YüksekCVSS 8,8İstismar yokEPSS %1

    gitea · gitea8 Şub 2022

  • CVE-2019-10330
    31İzleyin

    Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to chan

    YüksekCVSS 7,5İstismar yokEPSS %2

    gitea · gitea31 May 2019

  • CVE-2020-13246
    31İzleyin

    An issue was discovered in Gitea through 1.11.5.

    YüksekCVSS 7,5İstismar yokEPSS %2

    gitea · gitea20 May 2020

  • CVE-2021-3382
    31İzleyin

    Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors r

    YüksekCVSS 7,5İstismar yokEPSS %2

    gitea · gitea5 Şub 2021

  • CVE-2019-11228
    30İzleyin

    repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.

    YüksekCVSS 7,5İstismar yokEPSS %1

    gitea · gitea15 Nis 2019

  • CVE-2021-45325
    30İzleyin

    Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

    YüksekCVSS 7,5İstismar yokEPSS %1

    gitea · gitea8 Şub 2022

  • CVE-2022-27313
    30İzleyin

    An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration

    YüksekCVSS 7,5İstismar yokEPSS %1

    gitea · gitea3 May 2022

  • CVE-2026-20736
    30İzleyin

    Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check

    YüksekCVSS 7,5İstismar yokEPSS %0

    gitea · gitea22 Oca 2026