Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Server HIGH 8.8
CVE-2023-22381

A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environm…

Fix: 3.4.15 / 3.5.12+
Fix from $1,950 2023-03-02
Enterprise Server MEDIUM 6.5
CVE-2023-22380

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To e…

Fix: 3.7.6+
Fix from $1,600 2023-02-16
Cmark Gfm HIGH 7.5
CVE-2023-22486

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomia…

Fix: 0.29.0.gfm.7+
Fix from $1,950 2023-01-26
Cmark Gfm MEDIUM 5.3
CVE-2023-22485

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown …

Fix: 0.29.0.gfm.7+
Fix from $1,600 2023-01-24
Cmark Gfm HIGH 7.5
CVE-2023-22483

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to sever…

Fix: 0.29.0.gfm.7+
Fix from $1,950 2023-01-23
Cmark Gfm HIGH 7.5
CVE-2023-22484

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a pol…

Fix: 0.29.0.gfm.7+
Fix from $1,950 2023-01-23
Enterprise Server CRITICAL 9.8
CVE-2022-23739

An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests fr…

Fix: 3.3.16 / 3.4.11+
Fix from $2,300 2023-01-17
Enterprise Server MEDIUM 6.5
CVE-2022-46258

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to …

Fix: 3.3.16 / 3.4.11+
Fix from $1,600 2023-01-09
491 Project CRITICAL 9.8
CVE-2015-10031

A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the …

Fix: 2015-03-11+
Fix from $2,300 2023-01-08
Enterprise Server HIGH 7.2
CVE-2022-23741

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full ad…

Fix: 3.3.17 / 3.4.12+
Fix from $1,950 2022-12-14
Enterprise Server CRITICAL 9.8
CVE-2022-46255

An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code exec…

Mitigation only
Fix from $2,300 2022-12-14
Enterprise Server HIGH 8.8
CVE-2022-46256

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex…

Fix: 3.3.17 / 3.4.12+
Fix from $1,950 2022-12-14
Enterprise Server MEDIUM 6.5
CVE-2022-23737

An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or de…

Fix: 3.2.20 / 3.3.15+
Fix from $1,600 2022-12-01
Enterprise Server HIGH 8.8
CVE-2022-23740

CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote…

Mitigation only
Fix from $1,950 2022-11-23
Enterprise Server MEDIUM 5.7
CVE-2022-23738

An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files …

Fix: 3.2.20 / 3.3.15+
Fix from $1,600 2022-11-01
Runner CRITICAL 9.9
CVE-2022-39321

GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order …

Fix: 2.283.4 / 2.285.2+
Fix from $2,300 2022-10-25
Enterprise Server HIGH 8.8
CVE-2022-23734

A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on …

Fix: 3.2.16 / 3.3.11+
Fix from $1,950 2022-10-19
Cmark Gfm MEDIUM 6.5
CVE-2022-39209

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time…

Fix: 0.29.0.gfm.6+
Fix from $1,600 2022-09-15
Toolkit MEDIUM 5.0
CVE-2022-35954

The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…

Fix: 1.9.1+
Fix from $1,600 2022-08-15
Enterprise Server MEDIUM 5.4
CVE-2022-23733

A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked …

Fix: 3.3.11 / 3.4.6+
Fix from $1,600 2022-08-02
Enterprise Server HIGH 8.8
CVE-2022-23732

A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could …

Fix: 3.1.19 / 3.2.11+
Fix from $1,950 2022-04-05
Cmark Gfm CRITICAL 9.8
CVE-2022-24724

cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer …

Fix: 0.28.3.gfm.21 / 0.29.0.gfm.3+
Fix from $2,300 2022-03-03
Viewcomponent MEDIUM 6.1
CVE-2022-24722

VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulner…

Fix: 2.31.2 / 2.49.1+
Fix from $1,600 2022-03-02
Enterprise Server HIGH 8.8
CVE-2021-41599

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploi…

Fix: 3.0.21 / 3.1.13+
Fix from $1,950 2022-02-18
Gh Ost MEDIUM 6.5
CVE-2022-21687

gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The …

Fix: 1.1.3+
Fix from $1,600 2022-02-01
Enterprise Server HIGH 8.8
CVE-2021-41598

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's use…

Fix: 3.0.21 / 3.1.13+
Fix from $1,950 2022-01-25
Enterprise Server MEDIUM 6.5
CVE-2021-22870

A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. T…

Fix: 3.0.19 / 3.1.11+
Fix from $1,600 2021-11-10
Enterprise Server CRITICAL 9.8
CVE-2021-22869

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not ha…

Fix: 3.0.16 / 3.1.8+
Fix from $2,300 2021-09-24
Enterprise Server MEDIUM 6.5
CVE-2021-22867

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled …

Fix: 2.22.17 / 3.0.11+
Fix from $1,600 2021-07-14
Enterprise Server HIGH 8.8
CVE-2021-22866

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's use…

Fix: 2.22.13 / 3.0.7+
Fix from $1,950 2021-05-14