Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Server MEDIUM 6.5
CVE-2021-22865

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web auth…

Fix: 2.21.18 / 2.22.10+
Fix from $1,600 2021-04-02
Enterprise Server HIGH 8.8
CVE-2021-22864

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.21.17 / 2.22.9+
Fix from $1,950 2021-03-23
GitHub HIGH 8.1
CVE-2021-22863

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance …

Fix: 2.20.24 / 2.21.15+
Fix from $1,950 2021-03-03
GitHub MEDIUM 6.5
CVE-2021-22861

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write ac…

Fix: 2.20.24 / 2.21.15+
Fix from $1,600 2021-03-03
GitHub MEDIUM 6.5
CVE-2021-22862

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a rep…

Mitigation only
Fix from $1,600 2021-03-03
GitHub HIGH 8.8
CVE-2020-10519

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.20.24 / 2.21.15+
Fix from $1,950 2021-03-03
GitHub HIGH 8.8
CVE-2020-10518

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-cont…

Fix: 2.19.21 / 2.20.15+
Fix from $1,950 2020-08-27
GitHub CRITICAL 9.8
CVE-2020-10516

An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissio…

Fix: 2.18.20 / 2.19.15+
Fix from $2,300 2020-06-03
GitHub CRITICAL 9.8
CVE-2017-18365EPSS 21%

The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute ar…

Fix: 2.8.7+
Fix from $2,300 2019-03-28
Gaug.es MEDIUM 5.8
CVE-2012-5814

Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Nam…

No fix yet
Fix from $1,600 2012-11-04
GitHub HIGH 7.5
CVE-2012-2055

GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attack…

Fix: 20120304+
Fix from $1,950 2012-04-05