VYPR

Vendor CVEs

GitHub

All CVEs

600 total · sorted by risk
  • CVE-2023-6803MedDec 21, 2023
    risk 0.38cvss 5.8epss 0.00

    A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

  • CVE-2022-36072MedSep 6, 2022
    risk 0.38cvss 5.9epss 0.01

    SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobvious feature of PHP, hashes generated by built-in functions and starting with the `0e` symbols were being handled as zero multiplied with the `e` number.…

  • CVE-2026-40283MedApr 17, 2026
    risk 0.37cvss 6.8epss 0.00

    WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the "Nome" field in the "Informações Pacientes" page. The payload is stored and…

  • CVE-2026-23653MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

  • CVE-2022-23738MedNov 1, 2022
    risk 0.37cvss 5.7epss 0.01

    An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server…

  • CVE-2022-21687MedFeb 1, 2022
    risk 0.37cvss 6.8epss 0.01

    gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The attacker must have access to the target host or trick an administrator into executing a malicious gh-ost command on a host running…

  • CVE-2025-52569MedJun 25, 2025
    risk 0.36cvss —epss 0.00

    GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field.…

  • CVE-2025-50178MedJun 25, 2025
    risk 0.36cvss —epss 0.00

    GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certain functions. In the `GitForge.get_repo` function for GitHub, the user can provide any string for the owner and repo fields. These…

  • CVE-2025-23040MedJan 15, 2025
    risk 0.36cvss 6.6epss 0.01

    GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL.…

  • CVE-2024-2440MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise…

  • CVE-2023-40166MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.00

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory…

  • CVE-2026-62949MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asyncssh/connection.py accept a…

  • CVE-2026-64654MedAug 6, 2026
    risk 0.35cvss —epss 0.01

    GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who…

  • CVE-2026-39966MedMay 22, 2026
    risk 0.35cvss 6.5epss 0.00

    TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who references a target bot ID in a Typebot Link block, regardless of workspace ownership, leading to IDOR. The authorization check…

  • CVE-2026-23483MedMar 23, 2026
    risk 0.35cvss 5.3epss 0.01

    Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there…

  • CVE-2026-2266MedMar 10, 2026
    risk 0.35cvss 5.4epss 0.00

    An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic did not properly re-encode browser-decoded text nodes before rendering, allowing…

  • CVE-2025-13744MedJan 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An…

  • CVE-2025-64084MedNov 14, 2025
    risk 0.35cvss 5.4epss 0.00

    An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute…

  • CVE-2024-55651MedMay 8, 2025
    risk 0.35cvss 5.4epss 0.00

    i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuário) input field. Through…

  • CVE-2025-30363MedMar 27, 2025
    risk 0.35cvss 5.4epss 0.00

    WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.2.6. This vulnerability allows unauthorized scripts to be executed within the user's browser context. Stored XSS is particularly critical,…

  • CVE-2025-30362MedMar 27, 2025
    risk 0.35cvss 5.4epss 0.00

    WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.2.8. This vulnerability allows unauthorized scripts to be executed within the user's browser context. Stored XSS is particularly critical,…

  • CVE-2025-1595MedFeb 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects unknown code of the file /api/v1/getbaseconfig. The manipulation leads to information disclosure. The attack can be initiated…

  • CVE-2025-24967MedFeb 4, 2025
    risk 0.35cvss 5.4epss 0.00

    reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by injecting malicious payloads into the username field during…

  • CVE-2023-22485MedJan 24, 2023
    risk 0.35cvss 5.3epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown document can trigger an out-of-bounds read in the `validate_protocol` function. We believe this bug is harmless in practice,…

  • CVE-2022-23733MedAug 2, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and…

  • CVE-2021-40966MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will…

  • CVE-2021-37700MedAug 12, 2021
    risk 0.35cvss 6.5epss 0.02

    @github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string ``, a **div** is dynamically created, and the clipboard…

  • CVE-2021-32754MedJul 12, 2021
    risk 0.35cvss 5.3epss 0.01

    FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from external locations. In order for this to…

  • CVE-2026-81380MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-45040MedMay 28, 2026
    risk 0.34cvss —epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT…

  • CVE-2026-42344MedMay 8, 2026
    risk 0.34cvss 6.3epss 0.00

    FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding (TOCTOU — Time-of-Check to Time-of-Use). The function resolves the hostname via…

  • CVE-2026-27020MedFeb 20, 2026
    risk 0.34cvss —epss 0.00

    Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inject scripts through unvalidated form inputs. This vulnerability is fixed in 1.0.1.

  • CVE-2025-27776MedMar 19, 2025
    risk 0.34cvss 5.3epss 0.01

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 240 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for…

  • CVE-2025-27775MedMar 19, 2025
    risk 0.34cvss 5.3epss 0.01

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 143 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for…

  • CVE-2025-27774MedMar 19, 2025
    risk 0.34cvss 5.3epss 0.01

    Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 156 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for…

  • CVE-2024-6395MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. This vulnerability did not allow unauthorized access to any repository content besides the name. This…

  • CVE-2024-6336MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.00

    A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member to explicitly change the…

  • CVE-2024-5816MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not…

  • CVE-2023-46646MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check run" API endpoint. This vulnerability did not allow unauthorized access to any repository content besides the name. This…

  • CVE-2023-41889MedSep 15, 2023
    risk 0.34cvss 5.3epss 0.01

    SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The Unicode character equivalent of a…

  • CVE-2023-23763MedSep 1, 2023
    risk 0.34cvss 5.3epss 0.01

    An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. This vulnerability affected all versions of GitHub…

  • CVE-2026-64653MedAug 6, 2026
    risk 0.33cvss —epss 0.01

    GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different…

  • CVE-2026-42872MedMay 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of user-supplied input. The id_processo parameter is directly embedded into the HTML…

  • CVE-2025-62453MedNov 11, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-76450MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of…

  • CVE-2026-76428MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without…

  • CVE-2026-41412MedJun 2, 2026
    risk 0.32cvss 4.9epss 0.00

    alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every extension script's scope. The…

  • CVE-2023-51379MedDec 21, 2023
    risk 0.32cvss 4.9epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and…

  • CVE-2023-23760MedMar 8, 2023
    risk 0.32cvss 4.9epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise…

  • CVE-2023-23765MedAug 30, 2023
    risk 0.31cvss 4.8epss 0.01

    An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability…

Page 6 of 12