İçeriğe atla
Noroxi

gogs kayıtları

gogs üreticisine ait 49 yayımlanmış kayıt.

Tüm kayıtlar

49 kayıt
  • File overwrite in file update API in Gogs

    YüksekCVSS 8,7KEVSilahlaştırılmışEPSS %85

    gogs · gogs10 Ara 2025

  • CVE-2022-2024
    68Bu hafta

    OS Command Injection in gogs/gogs

    KritikCVSS 9,8İstismar yokEPSS %98

    gogs · gogs25 Şub 2023

  • CVE-2024-55947
    57Planlayın

    Gogs has a Path Traversal in file update API

    YüksekCVSS 8,7Kavram kanıtıEPSS %78

    gogs · gogs23 Ara 2024

  • CVE-2022-0415
    55Planlayın

    Remote Command Execution in uploading repository file in gogs/gogs

    YüksekCVSS 8,8Kavram kanıtıEPSS %65

    gogs · gogs21 Mar 2022

  • CVE-2024-39931
    55Planlayın

    Gogs through 0.13.0 allows deletion of internal files.

    KritikCVSS 9,9İstismar yokEPSS %53

    gogs · gogs4 Tem 2024

  • CVE-2020-15867
    54Planlayın

    The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.

    YüksekCVSS 7,2SilahlaştırılmışEPSS %87

    gogs · gogs16 Eki 2020

  • CVE-2022-32174
    53Planlayın

    In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

    KritikCVSS 9,0İstismar yokEPSS %58

    gogs · gogs11 Eki 2022

  • CVE-2018-18925
    48Planlayın

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    KritikCVSS 9,8Kavram kanıtıEPSS %31

    gogs · gogs4 Kas 2018

  • CVE-2024-39932
    44Planlayın

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

    KritikCVSS 9,9İstismar yokEPSS %17

    gogs · gogs4 Tem 2024

  • CVE-2022-1993
    43Planlayın

    Path Traversal in gogs/gogs

    YüksekCVSS 8,1İstismar yokEPSS %36

    gogs · gogs9 Haz 2022

  • CVE-2024-39930
    41Planlayın

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    KritikCVSS 9,9Kavram kanıtıEPSS %8

    gogs · gogs4 Tem 2024

  • CVE-2024-44625
    40Planlayın

    Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

    YüksekCVSS 8,8Kavram kanıtıEPSS %17

    gogs · gogs15 Kas 2024

  • CVE-2022-1986
    40Planlayın

    OS Command Injection in gogs/gogs

    KritikCVSS 9,8İstismar yokEPSS %4

    gogs · gogs9 Haz 2022

  • CVE-2022-1884
    40Planlayın

    Remote Command Execution in gogs/gogs

    KritikCVSS 9,8İstismar yokEPSS %2

    gogs · gogs15 Kas 2024

  • CVE-2019-14544
    39İzleyin

    routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

    KritikCVSS 9,8İstismar yokEPSS %2

    gogs · gogs2 Ağu 2019

  • CVE-2024-56731
    39İzleyin

    Gogs deletion of internal files allows remote command execution

    KritikCVSS 9,8İstismar yokEPSS %1

    gogs · gogs24 Haz 2025

  • CVE-2022-1992
    37İzleyin

    Path Traversal in gogs/gogs

    KritikCVSS 9,1İstismar yokEPSS %2

    gogs · gogs9 Haz 2022

  • CVE-2025-64111
    37İzleyin

    Gogs's update .git/config file allows remote command execution

    KritikCVSS 9,3İstismar yokEPSS %1

    gogs · gogs6 Şub 2026

  • CVE-2026-25921
    37İzleyin

    Gogs: Cross-repository LFS object overwrite via missing content hash verification

    KritikCVSS 9,3İstismar yokEPSS %0

    gogs · gogs5 Mar 2026

  • CVE-2021-32546
    36İzleyin

    Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.

    YüksekCVSS 8,8İstismar yokEPSS %2

    gogs · gogs2 Haz 2022

  • CVE-2022-0871
    36İzleyin

    Missing Authorization in gogs/gogs

    KritikCVSS 9,1İstismar yokEPSS %1

    gogs · gogs11 Mar 2022

  • CVE-2018-15192
    35İzleyin

    An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

    YüksekCVSS 8,6İstismar yokEPSS %2

    gitea · gitea7 Ağu 2018

  • CVE-2018-15193
    35İzleyin

    A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li

    YüksekCVSS 8,8İstismar yokEPSS %1

    gogs · gogs7 Ağu 2018

  • CVE-2026-26194
    35İzleyin

    Gogs: Release tag option injection in release deletion

    YüksekCVSS 8,8İstismar yokEPSS %1

    gogs · gogs5 Mar 2026

  • CVE-2018-16409
    34İzleyin

    In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

    YüksekCVSS 8,6İstismar yokEPSS %1

    gogs · gogs3 Eyl 2018