Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2022-1993EPSS 52%
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
Gogs
0.12.9+
HIGH 8.8
CVE-2021-32546
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (r…
Gogs
0.12.8+
MEDIUM 6.5
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
Gogs
0.12.8+
MEDIUM 5.4
CVE-2022-1464
Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then…
Gogs
0.12.7+
HIGH 8.8
CVE-2022-0415EPSS 65%
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
Gogs
0.12.6+
CRITICAL 9.1
CVE-2022-0871
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
Gogs
0.12.5+
MEDIUM 5.3
CVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
Gogs
0.12.5+
HIGH 7.2
CVE-2020-15867EPSS 87%
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to th…
Gogs
after 0.12.2
MEDIUM 6.5
CVE-2020-14958
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Gogs
Patch available
MEDIUM 5.9
CVE-2020-9329
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs
after 0.11.91
CRITICAL 9.8
CVE-2019-14544
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
Gogs
Patch available
HIGH 7.5
CVE-2018-20303
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under …
Gogs
0.11.82.1218+
CRITICAL 9.8
CVE-2018-18925EPSS 31%
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the fi…
Gogs
after 0.11.66
MEDIUM 6.1
CVE-2018-17031
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, bec…
Gogs
No fix yet
HIGH 8.6
CVE-2018-16409
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Gogs
Mitigation only
HIGH 8.8
CVE-2018-15193
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
Gogs
No fix yet
MEDIUM 6.1
CVE-2018-15178
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an i…
Gogs
0.12+