Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2024-10001
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via…
Enterprise Server
3.11.6 / 3.12.10+
HIGH 8.8
CVE-2025-23369
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unau…
Enterprise Server
3.12.14 / 3.13.10+
CRITICAL 9.6
CVE-2024-52308
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ss…
Cli
2.62.0+
MEDIUM 6.5
CVE-2024-8810
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator.…
Enterprise Server
3.10.17 / 3.11.15+
MEDIUM 6.5
CVE-2024-10824
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret …
Enterprise Server
3.13.2+
CRITICAL 9.1
CVE-2024-10007
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to r…
Enterprise Server
3.11.17 / 3.12.11+
CRITICAL 9.1
CVE-2024-9487EPSS 25%
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to …
Enterprise Server
3.11.16 / 3.12.10+
MEDIUM 6.1
CVE-2024-8770
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to s…
Enterprise Server
3.10.17 / 3.11.15+
HIGH 7.5
CVE-2024-42471
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable t…
Actions\/artifact
2.1.7+
CRITICAL 9.8
CVE-2024-6800
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity provider…
Enterprise Server
3.10.16 / 3.11.14+
MEDIUM 6.5
CVE-2024-6337
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_reques…
Enterprise Server
3.10.16 / 3.11.14+
MEDIUM 5.3
CVE-2024-6395
An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.5
CVE-2024-5795
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sendi…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.5
CVE-2024-5815
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect …
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.5
CVE-2024-5817
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. Th…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 5.3
CVE-2024-5816
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repos…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 5.3
CVE-2024-6336
A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterp…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.5
CVE-2024-5566
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related…
Enterprise Server
3.9.17 / 3.10.14+
HIGH 7.2
CVE-2024-5746
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to g…
Enterprise Server
3.9.16 / 3.10.13+
CRITICAL 9.8
CVE-2024-4985
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the …
Enterprise Server
3.9.15 / 3.10.12+
MEDIUM 5.9
CVE-2024-2440
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation …
Enterprise Server
3.9.13 / 3.10.10+
HIGH 7.2
CVE-2024-3470
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to …
Enterprise Server
3.11.8 / 3.12.2+
HIGH 7.2
CVE-2024-3646
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…
Enterprise Server
3.9.13 / 3.10.10+
HIGH 7.2
CVE-2024-3684
A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management…
Enterprise Server
3.9.13 / 3.10.10+
MEDIUM 6.5
CVE-2024-1908
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitH…
Enterprise Server
3.8.16 / 3.9.11+
HIGH 7.2
CVE-2024-2443
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…
Enterprise Server
3.8.17 / 3.9.12+
HIGH 7.2
CVE-2024-2469
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected …
Enterprise Server
3.8.17 / 3.9.12+
MEDIUM 5.5
CVE-2024-25129
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read…
Codeql Cli
2.16.3+
MEDIUM 6.5
CVE-2024-1482
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public reposit…
Enterprise Server
3.9.10 / 3.10.7+
CRITICAL 9.1
CVE-2024-1369
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…
Enterprise Server
3.8.15 / 3.9.10+