Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2023-22381
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environm…
Enterprise Server
3.4.15 / 3.5.12+
MEDIUM 6.5
CVE-2023-22380
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To e…
Enterprise Server
3.7.6+
HIGH 7.5
CVE-2023-22486
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomia…
Cmark Gfm
0.29.0.gfm.7+
MEDIUM 5.3
CVE-2023-22485
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown …
Cmark Gfm
0.29.0.gfm.7+
HIGH 7.5
CVE-2023-22483
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to sever…
Cmark Gfm
0.29.0.gfm.7+
HIGH 7.5
CVE-2023-22484
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a pol…
Cmark Gfm
0.29.0.gfm.7+
CRITICAL 9.8
CVE-2022-23739
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests fr…
Enterprise Server
3.3.16 / 3.4.11+
MEDIUM 6.5
CVE-2022-46258
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to …
Enterprise Server
3.3.16 / 3.4.11+
CRITICAL 9.8
CVE-2015-10031
A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the …
491 Project
2015-03-11+
HIGH 7.2
CVE-2022-23741
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full ad…
Enterprise Server
3.3.17 / 3.4.12+
CRITICAL 9.8
CVE-2022-46255
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code exec…
Enterprise Server
Mitigation only
HIGH 8.8
CVE-2022-46256
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex…
Enterprise Server
3.3.17 / 3.4.12+
MEDIUM 6.5
CVE-2022-23737
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or de…
Enterprise Server
3.2.20 / 3.3.15+
HIGH 8.8
CVE-2022-23740
CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote…
Enterprise Server
Mitigation only
MEDIUM 5.7
CVE-2022-23738
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files …
Enterprise Server
3.2.20 / 3.3.15+
CRITICAL 9.9
CVE-2022-39321
GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order …
Runner
2.283.4 / 2.285.2+
HIGH 8.8
CVE-2022-23734
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on …
Enterprise Server
3.2.16 / 3.3.11+
MEDIUM 6.5
CVE-2022-39209
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time…
Cmark Gfm
0.29.0.gfm.6+
MEDIUM 5.0
CVE-2022-35954
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…
Toolkit
1.9.1+
MEDIUM 5.4
CVE-2022-23733
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked …
Enterprise Server
3.3.11 / 3.4.6+
HIGH 8.8
CVE-2022-23732
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could …
Enterprise Server
3.1.19 / 3.2.11+
CRITICAL 9.8
CVE-2022-24724
cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer …
Cmark Gfm
0.28.3.gfm.21 / 0.29.0.gfm.3+
MEDIUM 6.1
CVE-2022-24722
VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulner…
Viewcomponent
2.31.2 / 2.49.1+
HIGH 8.8
CVE-2021-41599
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploi…
Enterprise Server
3.0.21 / 3.1.13+
MEDIUM 6.5
CVE-2022-21687
gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The …
Gh Ost
1.1.3+
HIGH 8.8
CVE-2021-41598
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's use…
Enterprise Server
3.0.21 / 3.1.13+
MEDIUM 6.5
CVE-2021-22870
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. T…
Enterprise Server
3.0.19 / 3.1.11+
CRITICAL 9.8
CVE-2021-22869
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not ha…
Enterprise Server
3.0.16 / 3.1.8+
MEDIUM 6.5
CVE-2021-22867
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled …
Enterprise Server
2.22.17 / 3.0.11+
HIGH 8.8
CVE-2021-22866
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's use…
Enterprise Server
2.22.13 / 3.0.7+