git-scm records
41 published records for vendor git-scm.
Researcher profile
- Entered KEV
- 1 · 2.4%
- Weaponized
- 5 · 12.2%
- Pre-auth RCE
- 9
- With a fix record
- 95.1%
- Median publish → KEV
- 48 days
Recurring classes
- CWE-20 Improper Input Validation5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2018-17456Weaponized | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows rgit-scm · git · CWE-88 | Critical9.8 | — | 97.4% | Oct 6, 2018 |
63This week | CVE-2025-48384Weaponized | Git allows arbitrary code execution through broken config quotinggit-scm · git · CWE-59 | High8.0 | KEV | 4.2% | Jul 8, 2025 |
62This week | CVE-2014-9390Weaponized | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Critical9.8 | — | 75.6% | Feb 11, 2020 |
58Plan | CVE-2017-1000117Weaponized | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | High8.8 | — | 77.8% | Oct 4, 2017 |
57Plan | CVE-2021-21300Weaponized | malicious repositories can execute remote code while cloninggit-scm · git · CWE-59 | High7.5 | — | 88.5% | Mar 9, 2021 |
56Plan | CVE-2022-23521No exploit | gitattributes parsing integer overflow in gitgit-scm · git · CWE-190 | Critical9.8 | — | 56.3% | Jan 17, 2023 |
52Plan | CVE-2022-41903Proof of concept | Integer overflow in `git archive`, `git log --format` leading to RCE in gitgit-scm · git · CWE-190 | Critical9.8 | — | 44.3% | Jan 17, 2023 |
46Plan | CVE-2023-25652No exploit | "git apply --reject" partially-controlled arbitrary file writegit-scm · git · CWE-22 | High7.5 | — | 51.9% | Apr 25, 2023 |
46Plan | CVE-2018-11235Proof of concept | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can debian · debian linux · CWE-22 | High7.8 | — | 48.8% | May 30, 2018 |
46Plan | CVE-2017-14867No exploit | Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to sugit-scm · git · CWE-78 | High8.8 | — | 36.0% | Sep 28, 2017 |
44Plan | CVE-2016-2324No exploit | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whisuse · linux enterprise debuginfo · CWE-119 | Critical9.8 | — | 18.1% | Apr 8, 2016 |
44Plan | CVE-2016-2315No exploit | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long fsuse · linux enterprise debuginfo · CWE-119 | Critical9.8 | — | 17.3% | Apr 8, 2016 |
40Plan | CVE-2018-19486No exploit | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain caslinux · linux kernel · CWE-426 | Critical9.8 | — | 4.1% | Nov 23, 2018 |
40Plan | CVE-2019-1353No exploit | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | Critical9.8 | — | 2.2% | Jan 24, 2020 |
36Monitor | CVE-2019-1387No exploit | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | High8.8 | — | 4.4% | Dec 18, 2019 |
36Monitor | CVE-2022-39260No exploit | Git vulnerable to Remote Code Execution via Heap overflow in `git shell`git-scm · git · CWE-122 | High8.8 | — | 3.3% | Oct 19, 2022 |
36Monitor | CVE-2014-9938No exploit | contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to git-scm · git · CWE-116 | High8.8 | — | 2.3% | Mar 19, 2017 |
33Monitor | CVE-2020-5260Proof of concept | malicious URLs may cause Git to present stored credentials to the wrong servergit · git · CWE-20 | High7.5 | — | 10.0% | Apr 14, 2020 |
33Monitor | CVE-2022-41953No exploit | Git clone remote code execution vulnerability in git-for-windowsgit-scm · git · CWE-426 | High7.8 | — | 6.8% | Jan 17, 2023 |
33Monitor | CVE-2023-29007Proof of concept | Arbitrary configuration injection via `git submodule deinit`git-scm · git · CWE-74 | High7.8 | — | 6.1% | Apr 25, 2023 |
32Monitor | CVE-2019-19604No exploit | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x bgit-scm · git · CWE-78 | High7.8 | — | 3.7% | Dec 10, 2019 |
31Monitor | CVE-2018-11233No exploit | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathncanonical · ubuntu linux · CWE-125 | High7.5 | — | 4.5% | May 30, 2018 |
31Monitor | CVE-2008-5516No exploit | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | High7.5 | — | 4.4% | Jan 20, 2009 |
31Monitor | CVE-2020-11008No exploit | Malicious URLs can still cause Git to send a stored credential to the wrong servergit-scm · git · CWE-20 | High7.5 | — | 3.9% | Apr 21, 2020 |
31Monitor | CVE-2021-40330No exploit | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected crgit-scm · git | High7.5 | — | 2.9% | Aug 31, 2021 |
- CVE-2018-1745668This week
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r
CriticalCVSS 9.8WeaponizedEPSS 97%git-scm · gitOct 6, 2018
- CVE-2025-4838463This week
Git allows arbitrary code execution through broken config quoting
HighCVSS 8.0KEVWeaponizedEPSS 4%git-scm · gitJul 8, 2025
- CVE-2014-939062This week
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
CriticalCVSS 9.8WeaponizedEPSS 76%mercurial · mercurialFeb 11, 2020
- CVE-2017-100011758Plan
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
HighCVSS 8.8WeaponizedEPSS 78%git-scm · gitOct 4, 2017
- CVE-2021-2130057Plan
malicious repositories can execute remote code while cloning
HighCVSS 7.5WeaponizedEPSS 89%git-scm · gitMar 9, 2021
- CVE-2022-2352156Plan
gitattributes parsing integer overflow in git
CriticalCVSS 9.8No exploitEPSS 56%git-scm · gitJan 17, 2023
- CVE-2022-4190352Plan
Integer overflow in `git archive`, `git log --format` leading to RCE in git
CriticalCVSS 9.8Proof of conceptEPSS 44%git-scm · gitJan 17, 2023
- CVE-2023-2565246Plan
"git apply --reject" partially-controlled arbitrary file write
HighCVSS 7.5No exploitEPSS 52%git-scm · gitApr 25, 2023
- CVE-2018-1123546Plan
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can
HighCVSS 7.8Proof of conceptEPSS 49%debian · debian linuxMay 30, 2018
- CVE-2017-1486746Plan
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to su
HighCVSS 8.8No exploitEPSS 36%git-scm · gitSep 28, 2017
- CVE-2016-232444Plan
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whi
CriticalCVSS 9.8No exploitEPSS 18%suse · linux enterprise debuginfoApr 8, 2016
- CVE-2016-231544Plan
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long f
CriticalCVSS 9.8No exploitEPSS 17%suse · linux enterprise debuginfoApr 8, 2016
- CVE-2018-1948640Plan
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas
CriticalCVSS 9.8No exploitEPSS 4%linux · linux kernelNov 23, 2018
- CVE-2019-135340Plan
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
CriticalCVSS 9.8No exploitEPSS 2%git-scm · gitJan 24, 2020
- CVE-2019-138736Monitor
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
HighCVSS 8.8No exploitEPSS 4%git-scm · gitDec 18, 2019
- CVE-2022-3926036Monitor
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
HighCVSS 8.8No exploitEPSS 3%git-scm · gitOct 19, 2022
- CVE-2014-993836Monitor
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to
HighCVSS 8.8No exploitEPSS 2%git-scm · gitMar 19, 2017
- CVE-2020-526033Monitor
malicious URLs may cause Git to present stored credentials to the wrong server
HighCVSS 7.5Proof of conceptEPSS 10%git · gitApr 14, 2020
- CVE-2022-4195333Monitor
Git clone remote code execution vulnerability in git-for-windows
HighCVSS 7.8No exploitEPSS 7%git-scm · gitJan 17, 2023
- CVE-2023-2900733Monitor
Arbitrary configuration injection via `git submodule deinit`
HighCVSS 7.8Proof of conceptEPSS 6%git-scm · gitApr 25, 2023
- CVE-2019-1960432Monitor
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x b
HighCVSS 7.8No exploitEPSS 4%git-scm · gitDec 10, 2019
- CVE-2018-1123331Monitor
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathn
HighCVSS 7.5No exploitEPSS 4%canonical · ubuntu linuxMay 30, 2018
- CVE-2008-551631Monitor
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
HighCVSS 7.5No exploitEPSS 4%git · gitJan 20, 2009
- CVE-2020-1100831Monitor
Malicious URLs can still cause Git to send a stored credential to the wrong server
HighCVSS 7.5No exploitEPSS 4%git-scm · gitApr 21, 2020
- CVE-2021-4033031Monitor
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cr
HighCVSS 7.5No exploitEPSS 3%git-scm · gitAug 31, 2021