VYPR

Vendor CVEs

GitHub

All CVEs

600 total · sorted by risk
  • CVE-2023-23764MedJul 27, 2023
    risk 0.31cvss 4.8epss 0.01

    An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vulnerability affected GitHub…

  • CVE-2022-31026MedJun 9, 2022
    risk 0.31cvss 5.9epss 0.01

    Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. Users of the trilogy gem should…

  • CVE-2020-26219MedNov 11, 2020
    risk 0.31cvss 4.7epss 0.01

    touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an…

  • CVE-2026-47748MedJun 16, 2026
    risk 0.29cvss 5.5epss 0.00

    stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to an out-of-bounds reads error through PyTorch checkpoint pickle opcode parsing.…

  • CVE-2023-23766MedSep 22, 2023
    risk 0.29cvss 4.5epss 0.01

    An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions…

  • CVE-2015-10031MedJan 8, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is…

  • CVE-2026-39964MedMay 22, 2026
    risk 0.28cvss 5.4epss 0.00

    TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the…

  • CVE-2026-5512MedApr 21, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and…

  • CVE-2026-35046MedApr 6, 2026
    risk 0.28cvss 5.4epss 0.00

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary tags into recipe step instructions. The bleach.clean() sanitizer explicitly whitelists the…

  • CVE-2026-3582MedMar 10, 2026
    risk 0.28cvss 4.3epss 0.00

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve issues and commits from private and internal repositories via the search REST API…

  • CVE-2026-3306MedMar 10, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already…

  • CVE-2025-6981MedJul 15, 2025
    risk 0.28cvss 4.3epss 0.00

    An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability…

  • CVE-2025-6600MedJul 1, 2025
    risk 0.28cvss 4.3epss 0.00

    An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via…

  • CVE-2025-3124MedApr 17, 2025
    risk 0.28cvss 4.3epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to…

  • CVE-2024-9539MedOct 11, 2024
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required…

  • CVE-2024-7711MedAug 20, 2024
    risk 0.28cvss 4.3epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub…

  • CVE-2024-2748MedMar 21, 2024
    risk 0.28cvss 4.3epss 0.00

    A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub…

  • CVE-2022-46257MedMar 7, 2023
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in…

  • CVE-2021-22868MedSep 24, 2021
    risk 0.28cvss 4.3epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub…

  • CVE-2020-10517MedAug 27, 2020
    risk 0.28cvss 4.3epss 0.01

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any…

  • CVE-2020-12863MedJun 24, 2020
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

  • CVE-2026-45352MedMay 29, 2026
    risk 0.27cvss 5.3epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp-httplib (httplib.h) parses…

  • CVE-2026-27936MedMar 19, 2026
    risk 0.27cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1,…

  • CVE-2024-31451MedApr 16, 2024
    risk 0.27cvss 5.3epss 0.01

    DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1.

  • CVE-2023-22381MedMar 2, 2023
    risk 0.27cvss 4.1epss 0.01

    A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need…

  • CVE-2022-35954MedAug 15, 2022
    risk 0.26cvss 5.0epss 0.01

    The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that…

  • CVE-2026-30889MedMar 20, 2026
    risk 0.25cvss 4.9epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1,…

  • CVE-2025-62794LowOct 28, 2025
    risk 0.25cvss 3.8epss 0.00

    GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure…

  • CVE-2023-6690LowDec 21, 2023
    risk 0.25cvss 3.9epss 0.00

    A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and…

  • CVE-2026-54163MedJul 17, 2026
    risk 0.24cvss 4.7epss 0.00

    secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and…

  • CVE-2023-22486LowJan 26, 2023
    risk 0.23cvss 3.5epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service.…

  • CVE-2023-22484LowJan 23, 2023
    risk 0.23cvss 3.5epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a polynomial time complexity issue in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. This…

  • CVE-2023-22483LowJan 23, 2023
    risk 0.23cvss 3.5epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service.…

  • CVE-2026-59831MedJul 9, 2026
    risk 0.22cvss 4.4epss 0.00

    GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without…

  • CVE-2026-64652LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in…

  • CVE-2026-33514MedMay 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are…

  • CVE-2026-45009MedMay 15, 2026
    risk 0.21cvss 4.3epss 0.00

    phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user…

  • CVE-2025-8447LowAug 26, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker…

  • CVE-2026-3307LowApr 21, 2026
    risk 0.18cvss 2.7epss 0.00

    An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter…

  • CVE-2024-8263LowSep 23, 2024
    risk 0.18cvss 2.7epss 0.00

    An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9,…

  • CVE-2024-25129LowFeb 22, 2024
    risk 0.18cvss 2.7epss 0.01

    The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CLI is used to process…

  • CVE-2023-51380LowDec 21, 2023
    risk 0.18cvss 2.7epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12,…

  • CVE-2026-45803LowMay 15, 2026
    risk 0.16cvss 3.5epss 0.00

    `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view…

  • CVE-2023-1111LowMay 24, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2021-29473LowApr 26, 2021
    risk 0.16cvss 2.5epss 0.02

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and…

  • CVE-2026-64655LowAug 6, 2026
    risk 0.14cvss —epss 0.00

    GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without escaping regex metacharacters, so a user-supplied…

  • CVE-2025-48064LowMay 21, 2025
    risk 0.14cvss 3.3epss 0.00

    GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to…

  • CVE-2026-33394LowMar 19, 2026
    risk 0.11cvss 2.7epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure categories to moderators who…

  • CVE-2026-72924LowAug 25, 2026
    risk 0.07cvss —epss 0.00

    GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a service in a Codespace can therefore become…

  • CVE-2022-3552HigOct 17, 2022
    risk 0.07cvss 7.2epss 0.44

    Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.

Page 7 of 12