VYPR

Vendor CVEs

GitHub

All CVEs

600 total · sorted by risk
  • CVE-2022-2651CriAug 4, 2022
    risk 0.04cvss 9.8epss 0.15

    Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.

  • CVE-2004-1293Jan 10, 2005
    risk 0.04cvss —epss 0.14

    Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.

  • CVE-2023-5375MedOct 4, 2023
    risk 0.03cvss 6.1epss 0.35

    Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

  • CVE-2023-2564CriMay 7, 2023
    risk 0.03cvss 10.0epss 0.41

    OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

  • CVE-2023-0048HigJan 4, 2023
    risk 0.03cvss 8.8epss 0.32

    Code Injection in GitHub repository lirantal/daloradius prior to master-branch.

  • CVE-2023-0028MedJan 1, 2023
    risk 0.03cvss 5.7epss 0.56

    Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.

  • CVE-2002-0296May 31, 2002
    risk 0.03cvss —epss 0.01

    The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

  • CVE-2002-0211May 16, 2002
    risk 0.03cvss —epss 0.01

    Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

  • CVE-2023-2554HigMay 5, 2023
    risk 0.02cvss 7.2epss 0.29

    External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

  • CVE-2022-1713HigMay 16, 2022
    risk 0.01cvss 7.5epss 0.10

    SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

  • CVE-2022-0944HigMar 15, 2022
    risk 0.01cvss 7.2epss 0.09

    Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.

  • CVE-2026-11804MedJul 23, 2026
    risk 0.00cvss 5.2epss 0.00

    Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5;…

  • CVE-2026-15783MedJul 17, 2026
    risk 0.00cvss —epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…

  • CVE-2026-15343HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the…

  • CVE-2026-15007MedJul 17, 2026
    risk 0.00cvss —epss 0.01

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…

  • CVE-2026-50510HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

  • CVE-2026-47282MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-14340MedJul 1, 2026
    risk 0.00cvss 5.0epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because…

  • CVE-2026-10585MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The…

  • CVE-2026-9132MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a…

  • CVE-2026-9106MedJun 30, 2026
    risk 0.00cvss 5.5epss 0.00

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org…

  • CVE-2026-48529MedJun 26, 2026
    risk 0.00cvss 6.0epss 0.00

    GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent…

  • CVE-2026-31876MedMar 11, 2026
    risk 0.00cvss 5.4epss 0.00

    Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated…

  • CVE-2026-31852CriMar 11, 2026
    risk 0.00cvss 10.0epss 0.00

    Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this…

  • CVE-2026-28497CriMar 6, 2026
    risk 0.00cvss 9.1epss 0.00

    TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request…

  • CVE-2026-26975HigFeb 20, 2026
    risk 0.00cvss 8.8epss 0.02

    Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…

  • CVE-2026-24140LowJan 24, 2026
    risk 0.00cvss 2.7epss 0.00

    MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary…

  • CVE-2026-23729MedJan 16, 2026
    risk 0.00cvss 6.1epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarDescricao and…

  • CVE-2026-22249HigJan 15, 2026
    risk 0.00cvss 7.1epss 0.01

    Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename.…

  • CVE-2026-22693MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to…

  • CVE-2025-69221MedJan 7, 2026
    risk 0.00cvss 4.3epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat…

  • CVE-2025-66403MedDec 1, 2025
    risk 0.00cvss 4.6epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG files. The application accepts…

  • CVE-2025-62509HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files…

  • CVE-2025-27781CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) and pass that value to the…

  • CVE-2025-27779CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a path to a model) and pass that value to…

  • CVE-2025-27778CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of the Applio repository but not attached to…

  • CVE-2024-55630LowFeb 7, 2025
    risk 0.00cvss 3.3epss 0.00

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g.…

  • CVE-2024-50349MedJan 14, 2025
    risk 0.00cvss 4.7epss 0.01

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out…

  • CVE-2024-32465HigMay 14, 2024
    risk 0.00cvss 7.3epss 0.01

    Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source…

  • CVE-2024-32027CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

  • CVE-2024-0322CriJan 8, 2024
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-6778MedDec 18, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

  • CVE-2023-6461MedDec 1, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.

  • CVE-2023-6128MedNov 14, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-5904MedNov 7, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5903MedNov 7, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5902MedNov 7, 2023
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5901LowNov 7, 2023
    risk 0.00cvss 3.5epss 0.00

    Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5900LowNov 7, 2023
    risk 0.00cvss 3.5epss 0.00

    Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-2675CriNov 7, 2023
    risk 0.00cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.

Page 8 of 12