VYPR

Vendor CVEs

GitHub

All CVEs

586 total · sorted by risk
  • CVE-2022-1345CriApr 13, 2022
    risk 0.00cvss 9.0epss 0.01

    Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-1346CriApr 13, 2022
    risk 0.00cvss 9.0epss 0.01

    Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-1045MedApr 11, 2022
    risk 0.00cvss 5.4epss 0.02

    Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

  • CVE-2022-0936MedApr 11, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.

  • CVE-2022-1290MedApr 10, 2022
    risk 0.00cvss 5.4epss 0.02

    Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

  • CVE-2022-0990CriApr 4, 2022
    risk 0.00cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-1191HigMar 31, 2022
    risk 0.00cvss 8.1epss 0.01

    SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2022-1180LowMar 30, 2022
    risk 0.00cvss 3.5epss 0.01

    Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

  • CVE-2022-1032HigMar 29, 2022
    risk 0.00cvss 7.2epss 0.02

    Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2022-1033HigMar 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2022-0515MedMar 21, 2022
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.

  • CVE-2022-0514MedMar 21, 2022
    risk 0.00cvss 6.5epss 0.01

    Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

  • CVE-2022-1000CriMar 17, 2022
    risk 0.00cvss 9.8epss 0.02

    Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

  • CVE-2022-0986MedMar 16, 2022
    risk 0.00cvss 6.1epss 0.01

    Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

  • CVE-2022-0822MedMar 11, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0821MedMar 11, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0820MedMar 11, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0756MedMar 7, 2022
    risk 0.00cvss 6.5epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2022-0755MedMar 7, 2022
    risk 0.00cvss 4.3epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2021-3967HigFeb 26, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

  • CVE-2022-0726MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-0717CriFeb 23, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-0571MedFeb 14, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

  • CVE-2021-3813MedFeb 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

  • CVE-2022-0527MedFeb 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

  • CVE-2022-0526MedFeb 9, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

  • CVE-2022-21711HigJan 24, 2022
    risk 0.00cvss 7.1epss 0.01

    elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…

  • CVE-2021-3866MedJan 20, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

  • CVE-2021-4143MedJan 19, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

  • CVE-2021-3934HigNov 12, 2021
    risk 0.00cvss 7.5epss 0.01

    ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command

  • CVE-2021-32638MedMay 25, 2021
    risk 0.00cvss 4.4epss 0.00

    Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to…

  • CVE-2020-15272HigOct 26, 2020
    risk 0.00cvss 8.7epss 0.01

    In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has…

  • CVE-2020-5238MedJul 1, 2020
    risk 0.00cvss 6.5epss 0.02

    The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the…

  • CVE-2014-0177May 27, 2014
    risk 0.00cvss epss 0.00

    The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.

  • CVE-2012-5814Nov 4, 2012
    risk 0.00cvss epss 0.01

    Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an…

  • CVE-2011-5187Sep 20, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.

Page 12 of 12