Vendor CVEs
GitHub
All CVEs
586 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1345 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1346 | Cri | 0.00 | 9.0 | 0.01 | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-1045 | Med | 0.00 | 5.4 | 0.02 | Apr 11, 2022 | Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. | ||
| CVE-2022-0936 | Med | 0.00 | 5.4 | 0.01 | Apr 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. | ||
| CVE-2022-1290 | Med | 0.00 | 5.4 | 0.02 | Apr 10, 2022 | Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | ||
| CVE-2022-0990 | Cri | 0.00 | 9.1 | 0.01 | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||
| CVE-2022-1191 | Hig | 0.00 | 8.1 | 0.01 | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-1180 | Low | 0.00 | 3.5 | 0.01 | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | ||
| CVE-2022-1032 | Hig | 0.00 | 7.2 | 0.02 | Mar 29, 2022 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-1033 | Hig | 0.00 | 7.8 | 0.01 | Mar 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-0515 | Med | 0.00 | 4.3 | 0.00 | Mar 21, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | ||
| CVE-2022-0514 | Med | 0.00 | 6.5 | 0.01 | Mar 21, 2022 | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | ||
| CVE-2022-1000 | Cri | 0.00 | 9.8 | 0.02 | Mar 17, 2022 | Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. | ||
| CVE-2022-0986 | Med | 0.00 | 6.1 | 0.01 | Mar 16, 2022 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. | ||
| CVE-2022-0822 | Med | 0.00 | 5.4 | 0.01 | Mar 11, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0821 | Med | 0.00 | 6.5 | 0.01 | Mar 11, 2022 | Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0820 | Med | 0.00 | 6.1 | 0.01 | Mar 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0. | ||
| CVE-2022-0756 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0755 | Med | 0.00 | 4.3 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2021-3967 | Hig | 0.00 | 8.8 | 0.01 | Feb 26, 2022 | Improper Access Control in GitHub repository zulip/zulip prior to 4.10. | ||
| CVE-2022-0726 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-0717 | Cri | 0.00 | 9.1 | 0.01 | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-0571 | Med | 0.00 | 6.1 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2. | ||
| CVE-2021-3813 | Med | 0.00 | 6.5 | 0.01 | Feb 9, 2022 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. | ||
| CVE-2022-0527 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2022-0526 | Med | 0.00 | 6.1 | 0.01 | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | ||
| CVE-2022-21711 | Hig | 0.00 | 7.1 | 0.01 | Jan 24, 2022 | elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By… | ||
| CVE-2021-3866 | Med | 0.00 | 5.4 | 0.01 | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6. | ||
| CVE-2021-4143 | Med | 0.00 | 6.1 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | ||
| CVE-2021-3934 | Hig | 0.00 | 7.5 | 0.01 | Nov 12, 2021 | ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command | ||
| CVE-2021-32638 | Med | 0.00 | 4.4 | 0.00 | May 25, 2021 | Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to… | ||
| CVE-2020-15272 | Hig | 0.00 | 8.7 | 0.01 | Oct 26, 2020 | In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has… | ||
| CVE-2020-5238 | Med | 0.00 | 6.5 | 0.02 | Jul 1, 2020 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the… | ||
| CVE-2014-0177 | 0.00 | — | 0.00 | May 27, 2014 | The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file. | |||
| CVE-2012-5814 | 0.00 | — | 0.01 | Nov 4, 2012 | Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an… | |||
| CVE-2011-5187 | 0.00 | — | 0.01 | Sep 20, 2012 | Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors. |
- risk 0.00cvss 9.0epss 0.01
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.0epss 0.01
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 5.4epss 0.02
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
- risk 0.00cvss 5.4epss 0.02
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
- risk 0.00cvss 9.1epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
- risk 0.00cvss 8.1epss 0.01
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- risk 0.00cvss 3.5epss 0.01
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
- risk 0.00cvss 7.2epss 0.02
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 7.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
- risk 0.00cvss 6.5epss 0.01
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.
- risk 0.00cvss 9.8epss 0.02
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
- risk 0.00cvss 6.1epss 0.01
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.5epss 0.01
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- risk 0.00cvss 6.5epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 4.3epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- risk 0.00cvss 5.4epss 0.01
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
- risk 0.00cvss 6.5epss 0.01
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
- risk 0.00cvss 7.1epss 0.01
elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
- risk 0.00cvss 7.5epss 0.01
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
- risk 0.00cvss 4.4epss 0.00
Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to…
- risk 0.00cvss 8.7epss 0.01
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has…
- risk 0.00cvss 6.5epss 0.02
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the…
- CVE-2014-0177May 27, 2014risk 0.00cvss —epss 0.00
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
- CVE-2012-5814Nov 4, 2012risk 0.00cvss —epss 0.01
Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an…
- CVE-2011-5187Sep 20, 2012risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.
Page 12 of 12