Skip to content
Noroxi

ahacker1

24 credited records · 11 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline

    HighCVSS 7.4No exploitEPSS 0%

    github · enterprise serverSep 22, 2026

  • Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution

    HighCVSS 7.7No exploitEPSS 1%

    github · enterprise serverSep 1, 2026

  • An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories

    MediumCVSS 5.3No exploitEPSS 0%

    github · enterprise serverJul 1, 2026

  • CVE-2026-9312
    36Monitor

    Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint

    CriticalCVSS 9.2No exploitEPSS 1%

    github · enterprise serverMay 26, 2026

  • CVE-2026-5845
    28Monitor

    Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server

    HighCVSS 7.2No exploitEPSS 0%

    github · enterprise serverApr 21, 2026

  • CVE-2026-5512
    21Monitor

    Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API

    MediumCVSS 5.3No exploitEPSS 0%

    github · enterprise serverApr 21, 2026

  • CVE-2026-4296
    30Monitor

    Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass

    HighCVSS 7.5No exploitEPSS 1%

    github · enterprise serverApr 21, 2026

  • CVE-2026-3307
    21Monitor

    Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers

    MediumCVSS 5.3No exploitEPSS 0%

    github · enterprise serverApr 21, 2026

  • CVE-2026-3306
    21Monitor

    Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access

    MediumCVSS 5.3Proof of conceptEPSS 0%

    github · enterprise serverMar 10, 2026

  • CVE-2026-1999
    28Monitor

    Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests

    HighCVSS 7.1Proof of conceptEPSS 0%

    github · enterprise serverFeb 18, 2026

  • CVE-2026-1355
    24Monitor

    Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports

    MediumCVSS 6.0No exploitEPSS 0%

    github · enterprise serverFeb 18, 2026

  • CVE-2024-8810
    34Monitor

    Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access

    HighCVSS 8.7No exploitEPSS 0%

    github · enterprise serverNov 7, 2024

  • CVE-2024-7711
    21Monitor

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, an

    MediumCVSS 5.3No exploitEPSS 0%

    github · enterprise serverAug 20, 2024

  • CVE-2024-6800
    38Monitor

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity

    CriticalCVSS 9.5No exploitEPSS 2%

    github · enterprise serverAug 20, 2024

  • CVE-2024-6395
    25Monitor

    GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys

    MediumCVSS 6.3No exploitEPSS 0%

    github · enterprise serverJul 16, 2024

  • CVE-2024-5817
    23Monitor

    Improper authorization allows read access to issue content in GitHub Enterprise Server

    MediumCVSS 5.9No exploitEPSS 1%

    github · enterprise serverJul 16, 2024

  • CVE-2024-5816
    27Monitor

    Improper authorization allows persistent access in GitHub Enterprise Server

    MediumCVSS 6.9No exploitEPSS 1%

    github · enterprise serverJul 16, 2024

  • CVE-2024-5815
    27Monitor

    Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository

    MediumCVSS 6.8No exploitEPSS 0%

    github · enterprise serverJul 16, 2024

  • CVE-2024-1908
    26Monitor

    Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation

    MediumCVSS 6.5No exploitEPSS 1%

    github · enterprise serverMar 20, 2024

  • CVE-2024-1482
    26Monitor

    Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution

    MediumCVSS 6.5No exploitEPSS 0%

    github · enterprise serverFeb 14, 2024

  • CVE-2023-6847
    30Monitor

    Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data

    HighCVSS 7.5No exploitEPSS 1%

    github · enterprise serverDec 21, 2023

  • Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get

    MediumCVSS 5.3No exploitEPSS 1%

    github · enterprise serverDec 21, 2023

  • Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv

    CriticalCVSS 9.8No exploitEPSS 1%

    github · enterprise serverJan 17, 2023

  • Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files

    MediumCVSS 5.7No exploitEPSS 1%

    github · enterprise serverNov 1, 2022