Gogs contains a critical injection vulnerability in the Git rebase mechanism that can be exploited by any registered user without administrative privileges to execute code on the server.
Two Notepad++ vulnerabilities enable code execution through XML manipulation; they were patched in version 8.9.6.1, but attackers must already have access to the user directory.