Vendor CVEs
GitHub
All CVEs
586 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5353 | Med | 0.00 | 6.5 | 0.01 | Oct 3, 2023 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-5351 | Med | 0.00 | 5.4 | 0.00 | Oct 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-5084 | Low | 0.00 | 3.9 | 0.00 | Sep 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8. | ||
| CVE-2023-4928 | Hig | 0.00 | 7.2 | 0.01 | Sep 13, 2023 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | ||
| CVE-2023-40032 | Med | 0.00 | 5.5 | 0.00 | Sep 11, 2023 | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when… | ||
| CVE-2023-4879 | Med | 0.00 | 4.8 | 0.00 | Sep 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | ||
| CVE-2023-4877 | Hig | 0.00 | 7.5 | 0.00 | Sep 10, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92. | ||
| CVE-2023-4876 | Hig | 0.00 | 7.5 | 0.00 | Sep 10, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92. | ||
| CVE-2023-4754 | Med | 0.00 | 5.5 | 0.00 | Sep 4, 2023 | Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-4704 | Med | 0.00 | 4.9 | 0.01 | Sep 1, 2023 | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4655 | Med | 0.00 | 6.1 | 0.00 | Aug 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | ||
| CVE-2023-4654 | Low | 0.00 | 3.5 | 0.00 | Aug 31, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1. | ||
| CVE-2023-4653 | Med | 0.00 | 4.8 | 0.00 | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4652 | Med | 0.00 | 5.4 | 0.00 | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4650 | Med | 0.00 | 4.7 | 0.00 | Aug 31, 2023 | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4649 | Med | 0.00 | 5.4 | 0.00 | Aug 31, 2023 | Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. | ||
| CVE-2023-4624 | Low | 0.00 | 2.4 | 0.01 | Aug 30, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08. | ||
| CVE-2023-4561 | Med | 0.00 | 4.8 | 0.00 | Aug 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4. | ||
| CVE-2023-4435 | Med | 0.00 | 5.5 | 0.00 | Aug 20, 2023 | Improper Input Validation in GitHub repository hamza417/inure prior to build88. | ||
| CVE-2023-4381 | Med | 0.00 | 4.3 | 0.00 | Aug 16, 2023 | Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2020-28840 | Hig | 0.00 | 7.8 | 0.00 | Aug 11, 2023 | Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS). | ||
| CVE-2023-39518 | Med | 0.00 | 5.4 | 0.00 | Aug 8, 2023 | social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3. | ||
| CVE-2023-4189 | Med | 0.00 | 4.8 | 0.00 | Aug 5, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4188 | Cri | 0.00 | 9.1 | 0.01 | Aug 5, 2023 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4187 | Med | 0.00 | 4.8 | 0.00 | Aug 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-4158 | Med | 0.00 | 5.4 | 0.00 | Aug 4, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3. | ||
| CVE-2023-3982 | Med | 0.00 | 4.8 | 0.00 | Jul 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. | ||
| CVE-2023-3973 | Med | 0.00 | 6.1 | 0.00 | Jul 27, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3. | ||
| CVE-2023-37275 | Low | 0.00 | 3.1 | 0.00 | Jul 13, 2023 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including messages that are… | ||
| CVE-2023-3627 | Hig | 0.00 | 8.8 | 0.00 | Jul 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | ||
| CVE-2023-3580 | Med | 0.00 | 4.3 | 0.01 | Jul 10, 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | ||
| CVE-2023-3568 | Med | 0.00 | 6.3 | 0.00 | Jul 10, 2023 | Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||
| CVE-2023-37261 | Cri | 0.00 | 9.6 | 0.01 | Jul 7, 2023 | OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the Internet Card feature enabled; that is, OpenComputers 1.2.0 until 1.8.3 in their most common, default configurations. If the… | ||
| CVE-2023-3532 | Med | 0.00 | 5.4 | 0.01 | Jul 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1. | ||
| CVE-2023-3520 | Med | 0.00 | 4.6 | 0.00 | Jul 6, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | ||
| CVE-2023-3294 | Med | 0.00 | 6.1 | 0.00 | Jun 16, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7. | ||
| CVE-2023-3293 | Med | 0.00 | 4.8 | 0.01 | Jun 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. | ||
| CVE-2023-3073 | Med | 0.00 | 5.4 | 0.00 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | ||
| CVE-2023-3074 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-3070 | Med | 0.00 | 5.4 | 0.01 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-3067 | Med | 0.00 | 5.4 | 0.00 | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. | ||
| CVE-2023-3021 | Med | 0.00 | 5.4 | 0.00 | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4. | ||
| CVE-2023-3020 | Med | 0.00 | 6.1 | 0.01 | May 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4. | ||
| CVE-2023-3013 | Hig | 0.00 | 7.1 | 0.00 | May 31, 2023 | Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2. | ||
| CVE-2023-2954 | Med | 0.00 | 5.4 | 0.00 | May 29, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | ||
| CVE-2023-2949 | Med | 0.00 | 6.1 | 0.01 | May 28, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2840 | Cri | 0.00 | 9.8 | 0.01 | May 22, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. | ||
| CVE-2023-2566 | Med | 0.00 | 4.8 | 0.01 | May 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2553 | Med | 0.00 | 5.4 | 0.00 | May 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0. | ||
| CVE-2023-2552 | Hig | 0.00 | 8.8 | 0.00 | May 5, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. |
- risk 0.00cvss 6.5epss 0.01
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 3.9epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
- risk 0.00cvss 7.2epss 0.01
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
- risk 0.00cvss 5.5epss 0.00
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when…
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
- risk 0.00cvss 7.5epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.
- risk 0.00cvss 7.5epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 4.9epss 0.01
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
- risk 0.00cvss 3.5epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 4.7epss 0.00
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 5.4epss 0.00
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
- risk 0.00cvss 2.4epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.
- risk 0.00cvss 5.5epss 0.00
Improper Input Validation in GitHub repository hamza417/inure prior to build88.
- risk 0.00cvss 4.3epss 0.00
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 7.8epss 0.00
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
- risk 0.00cvss 5.4epss 0.00
social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 9.1epss 0.01
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3.
- risk 0.00cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2.
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3.
- risk 0.00cvss 3.1epss 0.00
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including messages that are…
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
- risk 0.00cvss 4.3epss 0.01
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
- risk 0.00cvss 6.3epss 0.00
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- risk 0.00cvss 9.6epss 0.01
OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the Internet Card feature enabled; that is, OpenComputers 1.2.0 until 1.8.3 in their most common, default configurations. If the…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
- risk 0.00cvss 4.6epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
- risk 0.00cvss 6.1epss 0.00
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.
- risk 0.00cvss 7.1epss 0.00
Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 9.8epss 0.01
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.
Page 9 of 12