Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cody HIGH 8.8
CVE-2023-46248

Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code E…

Fix: after 0.14.0
Fix from $1,950 2023-10-31
Sourcegraph HIGH 7.8
CVE-2022-41942

Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present i…

Fix: 4.1.0+
Fix from $1,950 2022-11-22
Sourcegraph HIGH 7.2
CVE-2022-41943

sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `custom…

Fix: 4.1.0+
Fix from $1,950 2022-11-22
Sourcegraph HIGH 7.2
CVE-2022-29171

Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserv…

Fix: 3.38.0+
Fix from $1,950 2022-05-06
Sourcegraph HIGH 8.8
CVE-2022-23642EPSS 74%

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` servi…

Fix: 3.37+
Fix from $1,950 2022-02-18
Sourcegraph MEDIUM 6.5
CVE-2022-23643

Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity i…

Fix: 3.35.2 / 3.36.3+
Fix from $1,600 2022-02-15
Sourcegraph MEDIUM 6.5
CVE-2021-43823

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in priva…

Fix: 3.33.2+
Fix from $1,600 2021-12-13
Sourcegraph MEDIUM 6.1
CVE-2020-12283

Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/…

Fix: 3.15.1+
Fix from $1,600 2020-04-30