Skip to content
Noroxi

github records

158 published records for vendor github.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

158 records
  • CVE-2024-0200
    61This week

    Unsafe Reflection in Github Enterprise Server leading to Command Injection

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    github · enterprise serverJan 16, 2024

  • Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server

    HighCVSS 8.8Proof of conceptEPSS 66%

    github · enterprise serverJan 16, 2024

  • An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed

    CriticalCVSS 9.5Proof of conceptEPSS 26%

    github · enterprise serverOct 10, 2024

  • The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to e

    CriticalCVSS 9.8WeaponizedEPSS 21%

    github · githubMar 28, 2019

  • An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication

    CriticalCVSS 10.0No exploitEPSS 3%

    github · enterprise serverMay 20, 2024

  • Integer overflow in table parsing extension leads to heap memory corruption

    CriticalCVSS 9.8No exploitEPSS 5%

    github · cmark-gfmMar 3, 2022

  • GitHub Actions Runner vulnerable to Docker Command Escaping

    CriticalCVSS 9.9No exploitEPSS 2%

    github · runnerOct 25, 2022

  • Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member

    CriticalCVSS 9.8No exploitEPSS 2%

    github · githubJun 3, 2020

  • Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE

    CriticalCVSS 9.8No exploitEPSS 2%

    github · enterprise serverDec 14, 2022

  • CommonMarker Integer Overflow Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    github · cmark-gfmJan 4, 2024

  • Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv

    CriticalCVSS 9.8No exploitEPSS 1%

    github · enterprise serverJan 17, 2023

  • Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group

    CriticalCVSS 9.8No exploitEPSS 1%

    github · enterprise serverSep 24, 2021

  • purpleparrots 491-Project Highscore update.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    github · 491-projectJan 8, 2023

  • CVE-2024-6800
    38Monitor

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity

    CriticalCVSS 9.5No exploitEPSS 2%

    github · enterprise serverAug 20, 2024

  • Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer

    CriticalCVSS 9.6No exploitEPSS 1%

    github · cliNov 14, 2024

  • CVE-2024-1374
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 3%

    github · enterprise serverFeb 13, 2024

  • CVE-2024-1355
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 2%

    github · enterprise serverFeb 13, 2024

  • CVE-2024-1378
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 2%

    github · enterprise serverFeb 13, 2024

  • CVE-2024-1359
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 2%

    github · enterprise serverFeb 13, 2024

  • CVE-2024-1369
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 2%

    github · enterprise serverFeb 13, 2024

  • CVE-2024-1372
    37Monitor

    Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console

    CriticalCVSS 9.1No exploitEPSS 2%

    github · enterprise serverFeb 13, 2024

  • Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    HighCVSS 8.8No exploitEPSS 4%

    github · githubAug 27, 2020

  • Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    HighCVSS 8.8No exploitEPSS 3%

    github · githubMar 3, 2021

  • Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server

    HighCVSS 8.8No exploitEPSS 2%

    github · enterprise serverMar 23, 2021

  • Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code execution

    HighCVSS 8.8No exploitEPSS 2%

    github · enterprise serverFeb 17, 2022