İçeriğe atla
Noroxi

github kayıtları

github üreticisine ait 158 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,6
Pre-auth RCE
9
Düzeltme kaydı olan
%81,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

158 kayıt
  • CVE-2024-0200
    61Bu hafta

    Unsafe Reflection in Github Enterprise Server leading to Command Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %72

    github · enterprise server16 Oca 2024

  • CVE-2024-0507
    55Planlayın

    Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server

    YüksekCVSS 8,8Kavram kanıtıEPSS %66

    github · enterprise server16 Oca 2024

  • CVE-2024-9487
    46Planlayın

    An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed

    KritikCVSS 9,5Kavram kanıtıEPSS %26

    github · enterprise server10 Eki 2024

  • CVE-2017-18365
    45Planlayın

    The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to e

    KritikCVSS 9,8SilahlaştırılmışEPSS %21

    github · github28 Mar 2019

  • CVE-2024-4985
    41Planlayın

    An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication

    KritikCVSS 10,0İstismar yokEPSS %3

    github · enterprise server20 May 2024

  • CVE-2022-24724
    40Planlayın

    Integer overflow in table parsing extension leads to heap memory corruption

    KritikCVSS 9,8İstismar yokEPSS %5

    github · cmark-gfm3 Mar 2022

  • CVE-2022-39321
    39İzleyin

    GitHub Actions Runner vulnerable to Docker Command Escaping

    KritikCVSS 9,9İstismar yokEPSS %2

    github · runner25 Eki 2022

  • CVE-2020-10516
    39İzleyin

    Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member

    KritikCVSS 9,8İstismar yokEPSS %2

    github · github3 Haz 2020

  • CVE-2022-46255
    39İzleyin

    Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE

    KritikCVSS 9,8İstismar yokEPSS %2

    github · enterprise server14 Ara 2022

  • CVE-2024-22051
    39İzleyin

    CommonMarker Integer Overflow Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    github · cmark-gfm4 Oca 2024

  • CVE-2022-23739
    39İzleyin

    Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv

    KritikCVSS 9,8İstismar yokEPSS %1

    github · enterprise server17 Oca 2023

  • CVE-2021-22869
    39İzleyin

    Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group

    KritikCVSS 9,8İstismar yokEPSS %1

    github · enterprise server24 Eyl 2021

  • CVE-2015-10031
    39İzleyin

    purpleparrots 491-Project Highscore update.php sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    github · 491-project8 Oca 2023

  • CVE-2024-6800
    38İzleyin

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity

    KritikCVSS 9,5İstismar yokEPSS %2

    github · enterprise server20 Ağu 2024

  • CVE-2024-52308
    38İzleyin

    Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer

    KritikCVSS 9,6İstismar yokEPSS %1

    github · cli14 Kas 2024

  • CVE-2024-1374
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %3

    github · enterprise server13 Şub 2024

  • CVE-2024-1355
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %2

    github · enterprise server13 Şub 2024

  • CVE-2024-1378
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %2

    github · enterprise server13 Şub 2024

  • CVE-2024-1359
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %2

    github · enterprise server13 Şub 2024

  • CVE-2024-1369
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %2

    github · enterprise server13 Şub 2024

  • CVE-2024-1372
    37İzleyin

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    KritikCVSS 9,1İstismar yokEPSS %2

    github · enterprise server13 Şub 2024

  • CVE-2020-10518
    36İzleyin

    Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    YüksekCVSS 8,8İstismar yokEPSS %4

    github · github27 Ağu 2020

  • CVE-2020-10519
    36İzleyin

    Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    YüksekCVSS 8,8İstismar yokEPSS %3

    github · github3 Mar 2021

  • CVE-2021-22864
    36İzleyin

    Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    YüksekCVSS 8,8İstismar yokEPSS %2

    github · enterprise server23 Mar 2021

  • CVE-2021-41599
    36İzleyin

    Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code execution

    YüksekCVSS 8,8İstismar yokEPSS %2

    github · enterprise server17 Şub 2022