Vendor CVEs
GitHub
All CVEs
586 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1719 | Med | 0.00 | 5.4 | 0.01 | Sep 29, 2022 | Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page | ||
| CVE-2022-3268 | Cri | 0.00 | 9.8 | 0.01 | Sep 22, 2022 | Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-3251 | Med | 0.00 | 5.3 | 0.01 | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-3223 | Med | 0.00 | 6.1 | 0.01 | Sep 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. | ||
| CVE-2022-39209 | Hig | 0.00 | 7.5 | 0.02 | Sep 15, 2022 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.… | ||
| CVE-2022-3148 | Med | 0.00 | 6.1 | 0.01 | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | ||
| CVE-2022-2901 | Hig | 0.00 | 7.1 | 0.01 | Sep 6, 2022 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. | ||
| CVE-2022-3123 | Med | 0.00 | 6.1 | 0.01 | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. | ||
| CVE-2022-2965 | Med | 0.00 | 4.3 | 0.01 | Aug 23, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7. | ||
| CVE-2022-2829 | Med | 0.00 | 5.4 | 0.01 | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-2821 | Hig | 0.00 | 7.5 | 0.01 | Aug 15, 2022 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | ||
| CVE-2022-2636 | Hig | 0.00 | 8.5 | 0.01 | Aug 5, 2022 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-2626 | Hig | 0.00 | 7.2 | 0.01 | Aug 5, 2022 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-2631 | Hig | 0.00 | 8.8 | 0.01 | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. | ||
| CVE-2022-2595 | Cri | 0.00 | 10.0 | 0.01 | Aug 1, 2022 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | ||
| CVE-2022-31564 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31549 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-2365 | Med | 0.00 | 5.4 | 0.00 | Jul 10, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. | ||
| CVE-2022-2342 | Med | 0.00 | 5.4 | 0.01 | Jul 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. | ||
| CVE-2022-31065 | Med | 0.00 | 6.5 | 0.01 | Jun 27, 2022 | BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),… | ||
| CVE-2022-2128 | Cri | 0.00 | 9.8 | 0.03 | Jun 20, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. | ||
| CVE-2022-2134 | Med | 0.00 | 6.5 | 0.01 | Jun 20, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. | ||
| CVE-2022-2113 | Med | 0.00 | 5.4 | 0.01 | Jun 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. | ||
| CVE-2022-2037 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. | ||
| CVE-2022-2029 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2028 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2027 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2026 | Med | 0.00 | 5.4 | 0.01 | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. | ||
| CVE-2022-2022 | Med | 0.00 | 5.4 | 0.01 | Jun 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7. | ||
| CVE-2022-1893 | Med | 0.00 | 4.6 | 0.01 | May 31, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1926 | Med | 0.00 | 4.9 | 0.01 | May 31, 2022 | Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1931 | Hig | 0.00 | 8.1 | 0.02 | May 31, 2022 | Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3. | ||
| CVE-2022-1909 | Med | 0.00 | 5.4 | 0.01 | May 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200. | ||
| CVE-2022-1815 | Hig | 0.00 | 7.5 | 0.06 | May 25, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. | ||
| CVE-2022-1825 | Med | 0.00 | 5.4 | 0.01 | May 23, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. | ||
| CVE-2022-1813 | Cri | 0.00 | 9.8 | 0.03 | May 22, 2022 | OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | ||
| CVE-2022-1775 | Cri | 0.00 | 9.8 | 0.02 | May 20, 2022 | Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-1803 | Med | 0.00 | 6.9 | 0.02 | May 20, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-1770 | Hig | 0.00 | 8.8 | 0.03 | May 20, 2022 | Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-1806 | Med | 0.00 | 6.1 | 0.01 | May 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18. | ||
| CVE-2022-1730 | Med | 0.00 | 4.6 | 0.01 | May 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. | ||
| CVE-2022-1774 | Med | 0.00 | 6.1 | 0.01 | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-1767 | Hig | 0.00 | 7.5 | 0.02 | May 18, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-1723 | Hig | 0.00 | 7.5 | 0.02 | May 17, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6. | ||
| CVE-2022-1379 | Cri | 0.00 | 9.1 | 0.02 | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal… | ||
| CVE-2022-1681 | Hig | 0.00 | 7.2 | 0.02 | May 12, 2022 | Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions | ||
| CVE-2022-1543 | Hig | 0.00 | 8.8 | 0.01 | Apr 29, 2022 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server. | ||
| CVE-2022-1509 | Cri | 0.00 | 9.9 | 0.05 | Apr 28, 2022 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. | ||
| CVE-2022-1022 | Med | 0.00 | 5.4 | 0.04 | Apr 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. | ||
| CVE-2022-1231 | Med | 0.00 | 6.1 | 0.02 | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example… |
- risk 0.00cvss 5.4epss 0.01
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 5.3epss 0.01
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
- risk 0.00cvss 7.5epss 0.02
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
- risk 0.00cvss 7.1epss 0.01
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
- risk 0.00cvss 4.3epss 0.01
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- risk 0.00cvss 7.5epss 0.01
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
- risk 0.00cvss 8.5epss 0.01
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 7.2epss 0.01
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
- risk 0.00cvss 10.0epss 0.01
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
- risk 0.00cvss 9.3epss 0.01
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),…
- risk 0.00cvss 9.8epss 0.03
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
- risk 0.00cvss 6.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
- risk 0.00cvss 8.0epss 0.01
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 8.0epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.
- risk 0.00cvss 4.6epss 0.01
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 4.9epss 0.01
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 8.1epss 0.02
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.
- risk 0.00cvss 7.5epss 0.06
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.
- risk 0.00cvss 9.8epss 0.03
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
- risk 0.00cvss 9.8epss 0.02
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 6.9epss 0.02
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 8.8epss 0.03
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.
- risk 0.00cvss 4.6epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
- risk 0.00cvss 6.1epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.
- risk 0.00cvss 9.1epss 0.02
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…
- risk 0.00cvss 7.2epss 0.02
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
- risk 0.00cvss 8.8epss 0.01
Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.
- risk 0.00cvss 9.9epss 0.05
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
- risk 0.00cvss 5.4epss 0.04
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
- risk 0.00cvss 6.1epss 0.02
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…
Page 11 of 12