Skip to content
Noroxi

https://github.com/silverwind

24 credited records · 24 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Gitea profile feed disclosure bypassing user visibility

    MediumCVSS 4.3No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea push mirror API bypass of DISABLE_NEW_PUSH policy

    MediumCVSS 4.9No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea repository media API stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea push-to-create bypass of FORCE_PRIVATE policy

    MediumCVSS 5.4No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea push mirror local path check uses the repository owner

    HighCVSS 7.1No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea issue attachment API allows changing comment attachments

    MediumCVSS 4.3No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea tag delete route deletes releases without release permission

    HighCVSS 8.1No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea migration memory exhaustion from zero page size

    MediumCVSS 6.5No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea OAuth2 refresh token grant accepts access tokens

    CriticalCVSS 9.1No exploitEPSS 0%

    gitea · gitea4 days ago

  • Gitea private repository access retained after rejected transfer

    MediumCVSS 4.3No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea Actions memory exhaustion through large static matrices

    HighCVSS 7.5No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS

    MediumCVSS 4.3No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea issue reference parsing CPU exhaustion

    MediumCVSS 6.5No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea review and execution mismatch through duplicate tree entries

    CriticalCVSS 9.1No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea fork workflow approval bypass through maintainer-triggered events

    CriticalCVSS 9.8No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea push mirror SSRF and forced writes to internal Git hosts

    HighCVSS 8.1No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea deploy key pushes acting as the repository owner

    HighCVSS 7.1No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea repository migration SSRF through DNS rebinding

    HighCVSS 7.5No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea SSRF through Git HTTP redirects in mirrors and fetches

    HighCVSS 7.5No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea fork workflow approval bypass through cancel and rerun

    HighCVSS 8.8No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea fork workflow job revival through later approval

    HighCVSS 8.8No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea trusted workflow cancellation by unapproved fork runs

    HighCVSS 7.5No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea migration and pull mirror SSRF through multi-answer DNS

    MediumCVSS 4.3No exploitEPSS 0%

    gitea · gitea5 days ago

  • Gitea migration SSRF through ALLOWED_DOMAINS address check bypass

    HighCVSS 7.7No exploitEPSS 0%

    gitea · gitea5 days ago