Vendor CVEs
GitHub
All CVEs
597 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1806 | Med | 0.00 | 6.1 | 0.01 | May 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18. | ||
| CVE-2022-1730 | Med | 0.00 | 4.6 | 0.01 | May 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. | ||
| CVE-2022-1774 | Med | 0.00 | 6.1 | 0.01 | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-1767 | Hig | 0.00 | 7.5 | 0.02 | May 18, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-1723 | Hig | 0.00 | 7.5 | 0.02 | May 17, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6. | ||
| CVE-2022-1379 | Cri | 0.00 | 9.1 | 0.02 | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal… | ||
| CVE-2022-1681 | Hig | 0.00 | 7.2 | 0.02 | May 12, 2022 | Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions | ||
| CVE-2022-1543 | Hig | 0.00 | 8.8 | 0.01 | Apr 29, 2022 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server. | ||
| CVE-2022-1509 | Cri | 0.00 | 9.9 | 0.05 | Apr 28, 2022 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context. | ||
| CVE-2022-1022 | Med | 0.00 | 5.4 | 0.04 | Apr 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. | ||
| CVE-2022-1231 | Med | 0.00 | 6.1 | 0.02 | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example… | ||
| CVE-2022-1345 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1346 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1045 | Med | 0.00 | 5.4 | 0.02 | Apr 11, 2022 | Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. | ||
| CVE-2022-0936 | Med | 0.00 | 5.4 | 0.01 | Apr 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. | ||
| CVE-2022-1290 | Med | 0.00 | 5.4 | 0.02 | Apr 10, 2022 | Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-0990 | Cri | 0.00 | 9.1 | 0.01 | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||
| CVE-2022-1191 | Hig | 0.00 | 8.1 | 0.01 | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-1180 | Low | 0.00 | 3.5 | 0.01 | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | ||
| CVE-2022-1032 | Hig | 0.00 | 7.2 | 0.02 | Mar 29, 2022 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-1033 | Hig | 0.00 | 7.8 | 0.01 | Mar 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-0515 | Med | 0.00 | 4.3 | 0.00 | Mar 21, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | ||
| CVE-2022-0514 | Med | 0.00 | 6.5 | 0.01 | Mar 21, 2022 | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | ||
| CVE-2022-1000 | Cri | 0.00 | 9.8 | 0.02 | Mar 17, 2022 | Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. | ||
| CVE-2022-0986 | Med | 0.00 | 6.1 | 0.01 | Mar 16, 2022 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. | ||
| CVE-2022-0822 | Med | 0.00 | 5.4 | 0.01 | Mar 11, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0821 | Med | 0.00 | 6.5 | 0.01 | Mar 11, 2022 | Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0820 | Med | 0.00 | 6.1 | 0.01 | Mar 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0756 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0755 | Med | 0.00 | 4.3 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2021-3967 | Hig | 0.00 | 8.8 | 0.01 | Feb 26, 2022 | Improper Access Control in GitHub repository zulip/zulip prior to 4.10. | ||
| CVE-2022-0726 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-0717 | Cri | 0.00 | 9.1 | 0.01 | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-0571 | Med | 0.00 | 6.1 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2. | ||
| CVE-2021-3813 | Med | 0.00 | 6.5 | 0.01 | Feb 9, 2022 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. | ||
| CVE-2022-0527 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2022-0526 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2022-21711 | Hig | 0.00 | 7.1 | 0.01 | Jan 24, 2022 | elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By… | ||
| CVE-2021-3866 | Med | 0.00 | 5.4 | 0.01 | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6. | ||
| CVE-2021-4143 | Med | 0.00 | 6.1 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | ||
| CVE-2021-3934 | Hig | 0.00 | 7.5 | 0.01 | Nov 12, 2021 | ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command | ||
| CVE-2021-32638 | Med | 0.00 | 4.4 | 0.00 | May 25, 2021 | Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to… | ||
| CVE-2020-15272 | Hig | 0.00 | 8.7 | 0.01 | Oct 26, 2020 | In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has… | ||
| CVE-2020-5238 | Med | 0.00 | 6.5 | 0.02 | Jul 1, 2020 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the… | ||
| CVE-2014-0177 | 0.00 | — | 0.00 | May 27, 2014 | The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file. | |||
| CVE-2012-5814 | 0.00 | — | 0.01 | Nov 4, 2012 | Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an… | |||
| CVE-2011-5187 | 0.00 | — | 0.01 | Sep 20, 2012 | Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors. |
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.
- risk 0.00cvss 4.6epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
- risk 0.00cvss 6.1epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.
- risk 0.00cvss 9.1epss 0.02
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…
- risk 0.00cvss 7.2epss 0.02
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
- risk 0.00cvss 8.8epss 0.01
Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.
- risk 0.00cvss 9.9epss 0.05
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
- risk 0.00cvss 5.4epss 0.04
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
- risk 0.00cvss 6.1epss 0.02
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…
- risk 0.00cvss 9.0epss 0.01
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.0epss 0.01
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 5.4epss 0.02
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
- risk 0.00cvss 5.4epss 0.02
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.1epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
- risk 0.00cvss 8.1epss 0.01
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- risk 0.00cvss 3.5epss 0.01
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
- risk 0.00cvss 7.2epss 0.02
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 7.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
- risk 0.00cvss 6.5epss 0.01
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.
- risk 0.00cvss 9.8epss 0.02
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
- risk 0.00cvss 6.1epss 0.01
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.5epss 0.01
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.5epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 4.3epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- risk 0.00cvss 5.4epss 0.01
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
- risk 0.00cvss 6.5epss 0.01
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 7.1epss 0.01
elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
- risk 0.00cvss 7.5epss 0.01
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
- risk 0.00cvss 4.4epss 0.00
Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to…
- risk 0.00cvss 8.7epss 0.01
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has…
- risk 0.00cvss 6.5epss 0.02
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the…
- CVE-2014-0177May 27, 2014risk 0.00cvss —epss 0.00
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
- CVE-2012-5814Nov 4, 2012risk 0.00cvss —epss 0.01
Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an…
- CVE-2011-5187Sep 20, 2012risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.
Page 12 of 12