Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Git HIGH 8.0
CVE-2025-48384 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acc…

Fix: 2.43.7 / 2.44.4+
Fix from $1,950 2025-07-08
Git HIGH 7.8
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clon…

Fix: 2.39.4 / 2.40.2+
Fix from $1,950 2024-05-14
Git HIGH 7.1
CVE-2024-32021

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repositor…

Fix: 2.39.4 / 2.40.2+
Fix from $1,950 2024-05-14
Git HIGH 7.8
CVE-2024-32004

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repos…

Fix: 2.39.4 / 2.40.2+
Fix from $1,950 2024-05-14
Git HIGH 7.8
CVE-2023-29007EPSS 6%

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a spe…

Fix: 2.30.9 / 2.31.8+
Fix from $1,950 2023-04-25
Git HIGH 7.5
CVE-2023-25652EPSS 52%

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by fe…

Fix: 2.30.9 / 2.31.8+
Fix from $1,950 2023-04-25
Git HIGH 7.5
CVE-2023-23946

Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.3…

Fix: 2.30.8 / 2.31.7+
Fix from $1,950 2023-02-14
Git MEDIUM 5.5
CVE-2023-22490

Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7,…

Fix: 2.30.8 / 2.31.7+
Fix from $1,600 2023-02-14
Git CRITICAL 9.8
CVE-2022-23521EPSS 56%

Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by …

Fix: after 2.38.2
Fix from $2,300 2023-01-17
Git CRITICAL 9.8
CVE-2022-41903EPSS 44%

Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality …

Fix: after 2.38.2
Fix from $2,300 2023-01-17
Git HIGH 7.8
CVE-2022-41953EPSS 7%

Git GUI is a convenient graphical tool that comes with Git for Windows. Its target audience is users who are uncomfortable with using Git on the comm…

Fix: 2.39.1+
Fix from $1,950 2023-01-17
Git HIGH 8.8
CVE-2022-39260

Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's pus…

Fix: 2.30.6 / 2.31.5+
Fix from $1,950 2022-10-19
Git MEDIUM 5.5
CVE-2022-39253

Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2…

Fix: 2.30.6 / 2.31.5+
Fix from $1,600 2022-10-19
Git HIGH 7.8
CVE-2022-29187

Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable…

Fix: 2.30.5 / 2.31.4+
Fix from $1,950 2022-07-12
Git HIGH 7.8
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untruste…

Fix: 2.35.2 / 13.4+
Fix from $1,950 2022-04-12
Git HIGH 7.5
CVE-2022-24975

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present …

Fix: after 2.35.1
Fix from $1,950 2022-02-11
Git HIGH 7.5
CVE-2021-40330

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-proto…

Fix: 2.30.1+
Fix from $1,950 2021-08-31
Git HIGH 7.5
CVE-2021-21300EPSS 89%

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as…

Fix: 2.17.6 / 2.18.5+
Fix from $1,950 2021-03-09
Git HIGH 7.5
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This b…

Fix: 2.17.5 / 2.18.4+
Fix from $1,950 2020-04-21
Git CRITICAL 9.8
CVE-2014-9390EPSS 75%

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on…

Fix: 0.21.3 / 1.8.5.6+
Fix from $2,300 2020-02-12
Git CRITICAL 9.8
CVE-2019-1353

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running …

Fix: 2.14.6 / 2.15.4+
Fix from $2,300 2020-01-24
Git HIGH 8.8
CVE-2019-1387

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clo…

Fix: 2.14.6 / 2.15.4+
Fix from $1,950 2019-12-18
Git HIGH 7.8
CVE-2019-19604

Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.2…

Fix: 2.20.0 / 2.21.1+
Fix from $1,950 2019-12-11
Git CRITICAL 9.8
CVE-2018-19486

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involv…

Fix: 2.19.2+
Fix from $2,300 2018-11-23
Git CRITICAL 9.8
CVE-2018-17456EPSS 97%

Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote cod…

Fix: 2.14.5 / 2.15.3+
Fix from $2,300 2018-10-06
Git MEDIUM 5.0
CVE-2018-1000021

GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal co…

Fix: after 2.15.1
Fix from $1,600 2018-02-09
Git MEDIUM 5.5
CVE-2017-15298

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted r…

Fix: after 2.14.2
Fix from $1,600 2017-10-14
Git HIGH 8.8
CVE-2017-1000117EPSS 78%

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that …

Fix: after 2.7.5
Fix from $1,950 2017-10-05
Git HIGH 8.8
CVE-2017-14867EPSS 36%

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support sub…

Fix: after 2.10.4
Fix from $1,950 2017-09-29
Git HIGH 8.8
CVE-2014-9938

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause cod…

Fix: 1.9.3+
Fix from $1,950 2017-03-20