Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Server CRITICAL 9.1
CVE-2024-1372

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1374

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1378

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1355

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1359

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server HIGH 8.0
CVE-2024-1354

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $1,950 2024-02-13
Enterprise Server MEDIUM 6.1
CVE-2024-1084

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires use…

Fix: 3.8.15 / 3.9.10+
Fix from $1,600 2024-02-13
Enterprise Server MEDIUM 6.5
CVE-2024-1082

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by d…

Fix: 3.8.15 / 3.9.10+
Fix from $1,600 2024-02-13
Enterprise Server CRITICAL 9.8
CVE-2024-0200EPSS 72%

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead …

Fix: 3.8.13 / 3.9.8+
Fix from $2,300 2024-01-16
Enterprise Server HIGH 8.8
CVE-2024-0507EPSS 66%

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability…

Fix: 3.8.13 / 3.9.8+
Fix from $1,950 2024-01-16
Cmark Gfm CRITICAL 9.8
CVE-2024-22051

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated rem…

Fix: 0.23.4 / 0.28.3.gfm.21+
Fix from $2,300 2024-01-04
Enterprise Server HIGH 7.5
CVE-2023-6847

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafte…

Fix: 3.9.7 / 3.10.4+
Fix from $1,950 2023-12-21
Enterprise Server MEDIUM 5.5
CVE-2023-6804

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must ha…

Fix: 3.8.12 / 3.9.7+
Fix from $1,600 2023-12-21
Enterprise Server MEDIUM 6.5
CVE-2023-6802

An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to g…

Fix: 3.8.12 / 3.9.7+
Fix from $1,600 2023-12-21
Enterprise Server MEDIUM 5.7
CVE-2023-6746

An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service tha…

Fix: 3.7.19 / 3.8.12+
Fix from $1,600 2023-12-21
Enterprise Server HIGH 7.5
CVE-2023-46648

An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a user invitation to …

Fix: 3.8.12 / 3.9.7+
Fix from $1,950 2023-12-21
Enterprise Server HIGH 7.0
CVE-2023-46649

A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs…

Fix: 3.7.19 / 3.8.12+
Fix from $1,950 2023-12-21
Enterprise Server HIGH 8.8
CVE-2023-46647

Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an edito…

Fix: 3.8.12 / 3.9.6+
Fix from $1,950 2023-12-21
Enterprise Server MEDIUM 5.3
CVE-2023-46646

Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check r…

Fix: 3.7.19 / 3.8.12+
Fix from $1,600 2023-12-21
Enterprise Server MEDIUM 6.5
CVE-2023-23766

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a r…

Fix: 3.6.17 / 3.7.15+
Fix from $1,600 2023-09-22
Enterprise Server MEDIUM 5.3
CVE-2023-23763

An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access …

Fix: 3.6.18 / 3.7.16+
Fix from $1,600 2023-09-01
Enterprise Server MEDIUM 6.5
CVE-2023-23765

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a r…

Fix: 3.6.16 / 3.7.13+
Fix from $1,600 2023-08-30
Enterprise Server HIGH 7.1
CVE-2023-23764

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within…

Fix: 3.7.9 / 3.8.2+
Fix from $1,950 2023-07-27
Cmark Gfm HIGH 7.5
CVE-2023-37463

cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polyno…

Fix: 0.29.0.gfm.12+
Fix from $1,950 2023-07-13
Pull Requests And Issues HIGH 7.8
CVE-2023-36867

Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability

Fix: 0.66.2+
Fix from $1,950 2023-07-11
Enterprise Server MEDIUM 5.3
CVE-2023-23762

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do…

Fix: 3.4.18 / 3.5.15+
Fix from $1,600 2023-04-07
Enterprise Server MEDIUM 5.3
CVE-2023-23761

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret …

Fix: 3.4.18 / 3.5.15+
Fix from $1,600 2023-04-07
Cmark Gfm HIGH 7.5
CVE-2023-24824

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may…

Fix: 0.29.0.gfm.10.+
Fix from $1,950 2023-03-31
Cmark Gfm HIGH 7.5
CVE-2023-26485

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may…

Fix: 0.29.0.gfm.10+
Fix from $1,950 2023-03-31
Enterprise Server HIGH 8.8
CVE-2023-23760

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex…

Fix: 3.4.17 / 3.5.14+
Fix from $1,950 2023-03-08