Vendor CVEs
GitHub
All CVEs
597 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0289 | Med | 0.00 | 5.4 | 0.01 | Jan 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master. | ||
| CVE-2019-25084 | Low | 0.00 | 3.5 | 0.01 | Dec 25, 2022 | A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | ||
| CVE-2022-4665 | Hig | 0.00 | 8.8 | 0.01 | Dec 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6. | ||
| CVE-2022-4630 | Med | 0.00 | 5.3 | 0.01 | Dec 21, 2022 | Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. | ||
| CVE-2022-4614 | Med | 0.00 | 5.4 | 0.00 | Dec 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11. | ||
| CVE-2022-4605 | Med | 0.00 | 5.4 | 0.01 | Dec 18, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2022-4502 | Med | 0.00 | 6.1 | 0.01 | Dec 15, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-4414 | Med | 0.00 | 6.1 | 0.00 | Dec 12, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | ||
| CVE-2022-4413 | Med | 0.00 | 6.1 | 0.01 | Dec 12, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | ||
| CVE-2022-4366 | Hig | 0.00 | 7.5 | 0.01 | Dec 8, 2022 | Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. | ||
| CVE-2022-4271 | Med | 0.00 | 5.4 | 0.01 | Dec 2, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. | ||
| CVE-2022-1719 | Med | 0.00 | 5.4 | 0.01 | Sep 29, 2022 | Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page | ||
| CVE-2022-3268 | Cri | 0.00 | 9.8 | 0.01 | Sep 22, 2022 | Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-3251 | Med | 0.00 | 5.3 | 0.01 | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-3223 | Med | 0.00 | 6.1 | 0.01 | Sep 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. | ||
| CVE-2022-39209 | Hig | 0.00 | 7.5 | 0.02 | Sep 15, 2022 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.… | ||
| CVE-2022-3148 | Med | 0.00 | 6.1 | 0.01 | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | ||
| CVE-2022-2901 | Hig | 0.00 | 7.1 | 0.01 | Sep 6, 2022 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. | ||
| CVE-2022-3123 | Med | 0.00 | 6.1 | 0.01 | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. | ||
| CVE-2022-2965 | Med | 0.00 | 4.3 | 0.01 | Aug 23, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7. | ||
| CVE-2022-2829 | Med | 0.00 | 5.4 | 0.01 | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-2821 | Hig | 0.00 | 7.5 | 0.01 | Aug 15, 2022 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | ||
| CVE-2022-2636 | Hig | 0.00 | 8.5 | 0.01 | Aug 5, 2022 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-2626 | Hig | 0.00 | 7.2 | 0.01 | Aug 5, 2022 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-2631 | Hig | 0.00 | 8.8 | 0.01 | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. | ||
| CVE-2022-2595 | Cri | 0.00 | 10.0 | 0.01 | Aug 1, 2022 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | ||
| CVE-2022-31564 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31549 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-2365 | Med | 0.00 | 5.4 | 0.00 | Jul 10, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. | ||
| CVE-2022-2342 | Med | 0.00 | 5.4 | 0.01 | Jul 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. | ||
| CVE-2022-31065 | Med | 0.00 | 6.5 | 0.01 | Jun 27, 2022 | BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),… | ||
| CVE-2022-2128 | Cri | 0.00 | 9.8 | 0.03 | Jun 20, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. | ||
| CVE-2022-2134 | Med | 0.00 | 6.5 | 0.01 | Jun 20, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. | ||
| CVE-2022-2113 | Med | 0.00 | 5.4 | 0.01 | Jun 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. | ||
| CVE-2022-2037 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. | ||
| CVE-2022-2029 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2028 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2027 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2026 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2022 | Med | 0.00 | 5.4 | 0.01 | Jun 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7. | ||
| CVE-2022-1893 | Med | 0.00 | 4.6 | 0.01 | May 31, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1926 | Med | 0.00 | 4.9 | 0.01 | May 31, 2022 | Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1931 | Hig | 0.00 | 8.1 | 0.02 | May 31, 2022 | Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1909 | Med | 0.00 | 5.4 | 0.01 | May 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200. | ||
| CVE-2022-1815 | Hig | 0.00 | 7.5 | 0.05 | May 25, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. | ||
| CVE-2022-1825 | Med | 0.00 | 5.4 | 0.01 | May 23, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | ||
| CVE-2022-1813 | Cri | 0.00 | 9.8 | 0.03 | May 22, 2022 | OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | ||
| CVE-2022-1775 | Cri | 0.00 | 9.8 | 0.02 | May 20, 2022 | Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-1803 | Med | 0.00 | 6.9 | 0.02 | May 20, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-1770 | Hig | 0.00 | 8.8 | 0.03 | May 20, 2022 | Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2. |
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
- risk 0.00cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely.…
- risk 0.00cvss 8.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
- risk 0.00cvss 5.3epss 0.01
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
- risk 0.00cvss 7.5epss 0.01
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.
- risk 0.00cvss 5.4epss 0.01
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 5.3epss 0.01
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
- risk 0.00cvss 7.5epss 0.02
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
- risk 0.00cvss 7.1epss 0.01
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
- risk 0.00cvss 4.3epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- risk 0.00cvss 7.5epss 0.01
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
- risk 0.00cvss 8.5epss 0.01
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 7.2epss 0.01
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
- risk 0.00cvss 10.0epss 0.01
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
- risk 0.00cvss 9.3epss 0.01
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),…
- risk 0.00cvss 9.8epss 0.03
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
- risk 0.00cvss 6.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
- risk 0.00cvss 8.0epss 0.01
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 8.0epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.
- risk 0.00cvss 4.6epss 0.01
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 4.9epss 0.01
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 8.1epss 0.02
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.
- risk 0.00cvss 7.5epss 0.05
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.
- risk 0.00cvss 9.8epss 0.03
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
- risk 0.00cvss 9.8epss 0.02
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 6.9epss 0.02
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 8.8epss 0.03
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
Page 11 of 12