VYPR

Vendor CVEs

GitHub

All CVEs

586 total · sorted by risk
  • CVE-2026-47282MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-14340MedJul 1, 2026
    risk 0.00cvss 5.0epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because…

  • CVE-2026-10585MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The…

  • CVE-2026-9132MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a…

  • CVE-2026-9106MedJun 30, 2026
    risk 0.00cvss 5.5epss 0.00

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org…

  • CVE-2026-48529MedJun 26, 2026
    risk 0.00cvss 6.0epss 0.00

    GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent…

  • CVE-2026-28384CriMar 12, 2026
    risk 0.00cvss epss 0.01

    An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and…

  • CVE-2026-31876MedMar 11, 2026
    risk 0.00cvss 5.4epss 0.00

    Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated…

  • CVE-2026-31852CriMar 11, 2026
    risk 0.00cvss 10.0epss 0.00

    Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this…

  • CVE-2026-28497CriMar 6, 2026
    risk 0.00cvss 9.1epss 0.00

    TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request…

  • CVE-2026-26975HigFeb 20, 2026
    risk 0.00cvss 8.8epss 0.01

    Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…

  • CVE-2026-24140LowJan 24, 2026
    risk 0.00cvss 2.7epss 0.00

    MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary…

  • CVE-2026-23729MedJan 16, 2026
    risk 0.00cvss 6.1epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarDescricao and…

  • CVE-2026-22249HigJan 15, 2026
    risk 0.00cvss 7.1epss 0.01

    Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename.…

  • CVE-2026-22693MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to…

  • CVE-2025-69221MedJan 7, 2026
    risk 0.00cvss 4.3epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat…

  • CVE-2025-66403MedDec 1, 2025
    risk 0.00cvss 4.6epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG files. The application accepts…

  • CVE-2025-62509HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files…

  • CVE-2025-27781CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take user-supplied input (e.g. a path to a model) and pass that value to the…

  • CVE-2025-27779CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a path to a model) and pass that value to…

  • CVE-2025-27778CriMar 19, 2025
    risk 0.00cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of the Applio repository but not attached to…

  • CVE-2024-55630LowFeb 7, 2025
    risk 0.00cvss 3.3epss 0.00

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g.…

  • CVE-2024-50349MedJan 14, 2025
    risk 0.00cvss 4.7epss 0.01

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out…

  • CVE-2024-32465HigMay 14, 2024
    risk 0.00cvss 7.3epss 0.01

    Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source…

  • CVE-2024-32027CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

  • CVE-2024-0322CriJan 8, 2024
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-6778MedDec 18, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

  • CVE-2023-6461MedDec 1, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.

  • CVE-2023-6128MedNov 14, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-5904MedNov 7, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5903MedNov 7, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5902MedNov 7, 2023
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5901LowNov 7, 2023
    risk 0.00cvss 3.5epss 0.00

    Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5900LowNov 7, 2023
    risk 0.00cvss 3.5epss 0.00

    Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-2675CriNov 7, 2023
    risk 0.00cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.

  • CVE-2023-5948MedNov 3, 2023
    risk 0.00cvss 5.5epss 0.00

    Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

  • CVE-2023-5899HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5898HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5897HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.

  • CVE-2023-5896MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4.

  • CVE-2023-5893HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5892MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5891MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5890MedNov 1, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5862LowOct 31, 2023
    risk 0.00cvss 3.3epss 0.00

    Missing Authorization in GitHub repository hamza417/inure prior to Build95.

  • CVE-2023-42804LowOct 30, 2023
    risk 0.00cvss 3.1epss 0.00

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain…

  • CVE-2023-4517MedOct 13, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.

  • CVE-2023-5556MedOct 12, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.

  • CVE-2023-5535HigOct 11, 2023
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to v9.0.2010.

  • CVE-2023-5521CriOct 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

Page 8 of 12