ahacker1
24 credited records · 11 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2026-77912No exploit | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipelinegithub · enterprise server · CWE-79 | High7.4 | — | 0.5% | Sep 22, 2026 |
30Monitor | CVE-2026-19118No exploit | Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code executiongithub · enterprise server · CWE-367 | High7.7 | — | 0.5% | Sep 1, 2026 |
21Monitor | CVE-2026-14340No exploit | An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesgithub · enterprise server · CWE-863 | Medium5.3 | — | 0.4% | Jul 1, 2026 |
36Monitor | CVE-2026-9312No exploit | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpointgithub · enterprise server · CWE-918 | Critical9.2 | — | 0.6% | May 26, 2026 |
28Monitor | CVE-2026-5845No exploit | Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Servergithub · enterprise server · CWE-639 | High7.2 | — | 0.5% | Apr 21, 2026 |
21Monitor | CVE-2026-5512No exploit | Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy APIgithub · enterprise server · CWE-201 | Medium5.3 | — | 0.5% | Apr 21, 2026 |
30Monitor | CVE-2026-4296No exploit | Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassgithub · enterprise server · CWE-185 | High7.5 | — | 0.7% | Apr 21, 2026 |
21Monitor | CVE-2026-3307No exploit | Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersgithub · enterprise server · CWE-639 | Medium5.3 | — | 0.5% | Apr 21, 2026 |
21Monitor | CVE-2026-3306Proof of concept | Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessgithub · enterprise server · CWE-639 | Medium5.3 | — | 0.4% | Mar 10, 2026 |
28Monitor | CVE-2026-1999Proof of concept | Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requestsgithub · enterprise server · CWE-863 | High7.1 | — | 0.3% | Feb 18, 2026 |
24Monitor | CVE-2026-1355No exploit | Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exportsgithub · enterprise server · CWE-862 | Medium6.0 | — | 0.4% | Feb 18, 2026 |
34Monitor | CVE-2024-8810No exploit | Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessgithub · enterprise server · CWE-269 | High8.7 | — | 0.4% | Nov 7, 2024 |
21Monitor | CVE-2024-7711No exploit | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, angithub · enterprise server · CWE-863 | Medium5.3 | — | 0.5% | Aug 20, 2024 |
38Monitor | CVE-2024-6800No exploit | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identitygithub · enterprise server · CWE-347 | Critical9.5 | — | 1.5% | Aug 20, 2024 |
25Monitor | CVE-2024-6395No exploit | GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keysgithub · enterprise server · CWE-200 | Medium6.3 | — | 0.5% | Jul 16, 2024 |
23Monitor | CVE-2024-5817No exploit | Improper authorization allows read access to issue content in GitHub Enterprise Servergithub · enterprise server · CWE-863 | Medium5.9 | — | 0.5% | Jul 16, 2024 |
27Monitor | CVE-2024-5816No exploit | Improper authorization allows persistent access in GitHub Enterprise Servergithub · enterprise server · CWE-863 | Medium6.9 | — | 0.5% | Jul 16, 2024 |
27Monitor | CVE-2024-5815No exploit | Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositorygithub · enterprise server · CWE-352 | Medium6.8 | — | 0.3% | Jul 16, 2024 |
26Monitor | CVE-2024-1908No exploit | Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalationgithub · enterprise server · CWE-269 | Medium6.5 | — | 0.6% | Mar 20, 2024 |
26Monitor | CVE-2024-1482No exploit | Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow executiongithub · enterprise server · CWE-863 | Medium6.5 | — | 0.4% | Feb 14, 2024 |
30Monitor | CVE-2023-6847No exploit | Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Datagithub · enterprise server · CWE-287 | High7.5 | — | 0.8% | Dec 21, 2023 |
21Monitor | CVE-2023-46646No exploit | Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get github · enterprise server · CWE-639 | Medium5.3 | — | 0.5% | Dec 21, 2023 |
39Monitor | CVE-2022-23739No exploit | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-servgithub · enterprise server · CWE-863 | Critical9.8 | — | 1.2% | Jan 17, 2023 |
22Monitor | CVE-2022-23738No exploit | Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo filesgithub · enterprise server · CWE-200 | Medium5.7 | — | 0.7% | Nov 1, 2022 |
- CVE-2026-7791229Monitor
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
HighCVSS 7.4No exploitEPSS 0%github · enterprise serverSep 22, 2026
- CVE-2026-1911830Monitor
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
HighCVSS 7.7No exploitEPSS 1%github · enterprise serverSep 1, 2026
- CVE-2026-1434021Monitor
An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories
MediumCVSS 5.3No exploitEPSS 0%github · enterprise serverJul 1, 2026
- CVE-2026-931236Monitor
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
CriticalCVSS 9.2No exploitEPSS 1%github · enterprise serverMay 26, 2026
- CVE-2026-584528Monitor
Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
HighCVSS 7.2No exploitEPSS 0%github · enterprise serverApr 21, 2026
- CVE-2026-551221Monitor
Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API
MediumCVSS 5.3No exploitEPSS 0%github · enterprise serverApr 21, 2026
- CVE-2026-429630Monitor
Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
HighCVSS 7.5No exploitEPSS 1%github · enterprise serverApr 21, 2026
- CVE-2026-330721Monitor
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
MediumCVSS 5.3No exploitEPSS 0%github · enterprise serverApr 21, 2026
- CVE-2026-330621Monitor
Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access
MediumCVSS 5.3Proof of conceptEPSS 0%github · enterprise serverMar 10, 2026
- CVE-2026-199928Monitor
Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests
HighCVSS 7.1Proof of conceptEPSS 0%github · enterprise serverFeb 18, 2026
- CVE-2026-135524Monitor
Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports
MediumCVSS 6.0No exploitEPSS 0%github · enterprise serverFeb 18, 2026
- CVE-2024-881034Monitor
Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access
HighCVSS 8.7No exploitEPSS 0%github · enterprise serverNov 7, 2024
- CVE-2024-771121Monitor
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, an
MediumCVSS 5.3No exploitEPSS 0%github · enterprise serverAug 20, 2024
- CVE-2024-680038Monitor
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity
CriticalCVSS 9.5No exploitEPSS 2%github · enterprise serverAug 20, 2024
- CVE-2024-639525Monitor
GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys
MediumCVSS 6.3No exploitEPSS 0%github · enterprise serverJul 16, 2024
- CVE-2024-581723Monitor
Improper authorization allows read access to issue content in GitHub Enterprise Server
MediumCVSS 5.9No exploitEPSS 1%github · enterprise serverJul 16, 2024
- CVE-2024-581627Monitor
Improper authorization allows persistent access in GitHub Enterprise Server
MediumCVSS 6.9No exploitEPSS 1%github · enterprise serverJul 16, 2024
- CVE-2024-581527Monitor
Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository
MediumCVSS 6.8No exploitEPSS 0%github · enterprise serverJul 16, 2024
- CVE-2024-190826Monitor
Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation
MediumCVSS 6.5No exploitEPSS 1%github · enterprise serverMar 20, 2024
- CVE-2024-148226Monitor
Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution
MediumCVSS 6.5No exploitEPSS 0%github · enterprise serverFeb 14, 2024
- CVE-2023-684730Monitor
Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data
HighCVSS 7.5No exploitEPSS 1%github · enterprise serverDec 21, 2023
- CVE-2023-4664621Monitor
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get
MediumCVSS 5.3No exploitEPSS 1%github · enterprise serverDec 21, 2023
- CVE-2022-2373939Monitor
Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv
CriticalCVSS 9.8No exploitEPSS 1%github · enterprise serverJan 17, 2023
- CVE-2022-2373822Monitor
Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files
MediumCVSS 5.7No exploitEPSS 1%github · enterprise serverNov 1, 2022