Vendor CVEs
GitHub
All CVEs
586 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-7711 | Med | 0.28 | 4.3 | 0.01 | Aug 20, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub… | ||
| CVE-2024-2748 | Med | 0.28 | 4.3 | 0.00 | Mar 21, 2024 | A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub… | ||
| CVE-2022-46257 | Med | 0.28 | 4.3 | 0.01 | Mar 7, 2023 | An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in… | ||
| CVE-2021-22868 | Med | 0.28 | 4.3 | 0.01 | Sep 24, 2021 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub… | ||
| CVE-2020-10517 | Med | 0.28 | 4.3 | 0.01 | Aug 27, 2020 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any… | ||
| CVE-2020-12863 | Med | 0.28 | 4.3 | 0.01 | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. | ||
| CVE-2026-45352 | Med | 0.27 | 5.3 | 0.00 | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp-httplib (httplib.h) parses… | ||
| CVE-2026-27936 | Med | 0.27 | 5.3 | 0.00 | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1,… | ||
| CVE-2024-31451 | Med | 0.27 | 5.3 | 0.01 | Apr 16, 2024 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1. | ||
| CVE-2023-22381 | Med | 0.27 | 4.1 | 0.01 | Mar 2, 2023 | A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need… | ||
| CVE-2022-35954 | Med | 0.26 | 5.0 | 0.01 | Aug 15, 2022 | The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that… | ||
| CVE-2026-30889 | Med | 0.25 | 4.9 | 0.00 | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1,… | ||
| CVE-2025-62794 | Low | 0.25 | 3.8 | 0.00 | Oct 28, 2025 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure… | ||
| CVE-2023-6690 | Low | 0.25 | 3.9 | 0.00 | Dec 21, 2023 | A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and… | ||
| CVE-2026-54163 | Med | 0.24 | 4.7 | 0.00 | Jul 17, 2026 | secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and… | ||
| CVE-2023-22486 | Low | 0.23 | 3.5 | 0.01 | Jan 26, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service.… | ||
| CVE-2023-22484 | Low | 0.23 | 3.5 | 0.01 | Jan 23, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a polynomial time complexity issue in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. This… | ||
| CVE-2023-22483 | Low | 0.23 | 3.5 | 0.01 | Jan 23, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service.… | ||
| CVE-2026-59831 | Med | 0.22 | 4.4 | 0.00 | Jul 9, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without… | ||
| CVE-2026-64652 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2026 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in… | ||
| CVE-2026-33514 | Med | 0.21 | 4.3 | 0.00 | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are… | ||
| CVE-2026-45009 | Med | 0.21 | 4.3 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user… | ||
| CVE-2025-8447 | Low | 0.20 | 3.1 | 0.00 | Aug 26, 2025 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker… | ||
| CVE-2026-3307 | Low | 0.18 | 2.7 | 0.00 | Apr 21, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter… | ||
| CVE-2024-8263 | Low | 0.18 | 2.7 | 0.00 | Sep 23, 2024 | An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9,… | ||
| CVE-2024-25129 | Low | 0.18 | 2.7 | 0.01 | Feb 22, 2024 | The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CLI is used to process… | ||
| CVE-2023-51380 | Low | 0.18 | 2.7 | 0.00 | Dec 21, 2023 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12,… | ||
| CVE-2026-45803 | Low | 0.16 | 3.5 | 0.00 | May 15, 2026 | `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view… | ||
| CVE-2023-1111 | Low | 0.16 | 2.4 | 0.00 | May 24, 2024 | A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The… | ||
| CVE-2021-29473 | Low | 0.16 | 2.5 | 0.02 | Apr 26, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and… | ||
| CVE-2026-64655 | Low | 0.14 | — | 0.00 | Aug 6, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without escaping regex metacharacters, so a user-supplied… | ||
| CVE-2025-48064 | Low | 0.14 | 3.3 | 0.00 | May 21, 2025 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to… | ||
| CVE-2026-33394 | Low | 0.11 | 2.7 | 0.00 | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure categories to moderators who… | ||
| CVE-2022-3552 | Hig | 0.07 | 7.2 | 0.44 | Oct 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1. | ||
| CVE-2022-2651 | Cri | 0.04 | 9.8 | 0.15 | Aug 4, 2022 | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | ||
| CVE-2004-1293 | 0.04 | — | 0.14 | Jan 10, 2005 | Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file. | |||
| CVE-2023-5375 | Med | 0.03 | 6.1 | 0.35 | Oct 4, 2023 | Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2. | ||
| CVE-2023-2564 | Cri | 0.03 | 10.0 | 0.41 | May 7, 2023 | OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. | ||
| CVE-2023-0048 | Hig | 0.03 | 8.8 | 0.32 | Jan 4, 2023 | Code Injection in GitHub repository lirantal/daloradius prior to master-branch. | ||
| CVE-2023-0028 | Med | 0.03 | 5.7 | 0.41 | Jan 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+. | ||
| CVE-2002-0296 | 0.03 | — | 0.01 | May 31, 2002 | The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file. | |||
| CVE-2002-0211 | 0.03 | — | 0.01 | May 16, 2002 | Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed. | |||
| CVE-2023-2554 | Hig | 0.02 | 7.2 | 0.29 | May 5, 2023 | External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0. | ||
| CVE-2022-1713 | Hig | 0.01 | 7.5 | 0.09 | May 16, 2022 | SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information. | ||
| CVE-2022-0944 | Hig | 0.01 | 7.2 | 0.09 | Mar 15, 2022 | Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1. | ||
| CVE-2026-11804 | Med | 0.00 | 5.2 | 0.00 | Jul 23, 2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5;… | ||
| CVE-2026-15783 | Med | 0.00 | — | 0.00 | Jul 17, 2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch… | ||
| CVE-2026-15343 | Hig | 0.00 | — | 0.00 | Jul 17, 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the… | ||
| CVE-2026-15007 | Med | 0.00 | — | 0.00 | Jul 17, 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the… | ||
| CVE-2026-50510 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. |
- risk 0.28cvss 4.3epss 0.01
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub…
- risk 0.28cvss 4.3epss 0.00
A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub…
- risk 0.28cvss 4.3epss 0.01
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in…
- risk 0.28cvss 4.3epss 0.01
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub…
- risk 0.28cvss 4.3epss 0.01
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any…
- risk 0.28cvss 4.3epss 0.01
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
- risk 0.27cvss 5.3epss 0.00
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp-httplib (httplib.h) parses…
- risk 0.27cvss 5.3epss 0.00
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1,…
- risk 0.27cvss 5.3epss 0.01
DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1.
- risk 0.27cvss 4.1epss 0.01
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need…
- risk 0.26cvss 5.0epss 0.01
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that…
- risk 0.25cvss 4.9epss 0.00
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1,…
- risk 0.25cvss 3.8epss 0.00
GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure…
- risk 0.25cvss 3.9epss 0.00
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and…
- risk 0.24cvss 4.7epss 0.00
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and…
- risk 0.23cvss 3.5epss 0.01
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service.…
- risk 0.23cvss 3.5epss 0.01
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a polynomial time complexity issue in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. This…
- risk 0.23cvss 3.5epss 0.01
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service.…
- risk 0.22cvss 4.4epss 0.00
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without…
- risk 0.21cvss 3.3epss 0.00
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in…
- risk 0.21cvss 4.3epss 0.00
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are…
- risk 0.21cvss 4.3epss 0.00
phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user…
- risk 0.20cvss 3.1epss 0.00
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker…
- risk 0.18cvss 2.7epss 0.00
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter…
- risk 0.18cvss 2.7epss 0.00
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9,…
- risk 0.18cvss 2.7epss 0.01
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CLI is used to process…
- risk 0.18cvss 2.7epss 0.00
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12,…
- risk 0.16cvss 3.5epss 0.00
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view…
- risk 0.16cvss 2.4epss 0.00
A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The…
- risk 0.16cvss 2.5epss 0.02
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and…
- risk 0.14cvss —epss 0.00
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without escaping regex metacharacters, so a user-supplied…
- risk 0.14cvss 3.3epss 0.00
GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to…
- risk 0.11cvss 2.7epss 0.00
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure categories to moderators who…
- risk 0.07cvss 7.2epss 0.44
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
- risk 0.04cvss 9.8epss 0.15
Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.
- CVE-2004-1293Jan 10, 2005risk 0.04cvss —epss 0.14
Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.
- risk 0.03cvss 6.1epss 0.35
Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
- risk 0.03cvss 10.0epss 0.41
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
- risk 0.03cvss 8.8epss 0.32
Code Injection in GitHub repository lirantal/daloradius prior to master-branch.
- risk 0.03cvss 5.7epss 0.41
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
- CVE-2002-0296May 31, 2002risk 0.03cvss —epss 0.01
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
- CVE-2002-0211May 16, 2002risk 0.03cvss —epss 0.01
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
- risk 0.02cvss 7.2epss 0.29
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
- risk 0.01cvss 7.5epss 0.09
SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
- risk 0.01cvss 7.2epss 0.09
Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
- risk 0.00cvss 5.2epss 0.00
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5;…
- risk 0.00cvss —epss 0.00
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…
- risk 0.00cvss —epss 0.00
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the…
- risk 0.00cvss —epss 0.00
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…
- risk 0.00cvss 7.8epss 0.00
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
Page 7 of 12