github records
158 published records for vendor github.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.6%
- Pre-auth RCE
- 9
- With a fix record
- 81.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-863 Incorrect Authorization14
- CWE-20 Improper Input Validation13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')9
- CWE-269 Improper Privilege Management8
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
158 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2024-0200Proof of concept | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Critical9.8 | — | 71.7% | Jan 16, 2024 |
55Plan | CVE-2024-0507Proof of concept | Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Servergithub · enterprise server · CWE-20 | High8.8 | — | 65.8% | Jan 16, 2024 |
46Plan | CVE-2024-9487Proof of concept | An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassedgithub · enterprise server · CWE-347 | Critical9.5 | — | 25.6% | Oct 10, 2024 |
45Plan | CVE-2017-18365Weaponized | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to egithub · github · CWE-502 | Critical9.8 | — | 21.2% | Mar 28, 2019 |
41Plan | CVE-2024-4985No exploit | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication github · enterprise server · CWE-303 | Critical10.0 | — | 2.6% | May 20, 2024 |
40Plan | CVE-2022-24724No exploit | Integer overflow in table parsing extension leads to heap memory corruptiongithub · cmark-gfm · CWE-190 | Critical9.8 | — | 4.5% | Mar 3, 2022 |
39Monitor | CVE-2022-39321No exploit | GitHub Actions Runner vulnerable to Docker Command Escapinggithub · runner · CWE-78 | Critical9.9 | — | 1.6% | Oct 25, 2022 |
39Monitor | CVE-2020-10516No exploit | Improper access control in GitHub Enterprise Server leading to privilege escalation of organization membergithub · github · CWE-285 | Critical9.8 | — | 1.6% | Jun 3, 2020 |
39Monitor | CVE-2022-46255No exploit | Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCEgithub · enterprise server · CWE-22 | Critical9.8 | — | 1.5% | Dec 14, 2022 |
39Monitor | CVE-2024-22051No exploit | CommonMarker Integer Overflow Vulnerabilitygithub · cmark-gfm · CWE-190 | Critical9.8 | — | 1.5% | Jan 4, 2024 |
39Monitor | CVE-2022-23739No exploit | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-servgithub · enterprise server · CWE-863 | Critical9.8 | — | 1.2% | Jan 17, 2023 |
39Monitor | CVE-2021-22869No exploit | Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupgithub · enterprise server · CWE-668 | Critical9.8 | — | 1.2% | Sep 24, 2021 |
39Monitor | CVE-2015-10031No exploit | purpleparrots 491-Project Highscore update.php sql injectiongithub · 491-project · CWE-89 | Critical9.8 | — | 0.7% | Jan 8, 2023 |
38Monitor | CVE-2024-6800No exploit | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identitygithub · enterprise server · CWE-347 | Critical9.5 | — | 1.5% | Aug 20, 2024 |
38Monitor | CVE-2024-52308No exploit | Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computergithub · cli · CWE-77 | Critical9.6 | — | 0.9% | Nov 14, 2024 |
37Monitor | CVE-2024-1374No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.6% | Feb 13, 2024 |
37Monitor | CVE-2024-1355No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.4% | Feb 13, 2024 |
37Monitor | CVE-2024-1378No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.3% | Feb 13, 2024 |
37Monitor | CVE-2024-1359No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.3% | Feb 13, 2024 |
37Monitor | CVE-2024-1369No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.3% | Feb 13, 2024 |
37Monitor | CVE-2024-1372No exploit | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Critical9.1 | — | 2.3% | Feb 13, 2024 |
36Monitor | CVE-2020-10518No exploit | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | High8.8 | — | 3.7% | Aug 27, 2020 |
36Monitor | CVE-2020-10519No exploit | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | High8.8 | — | 3.1% | Mar 3, 2021 |
36Monitor | CVE-2021-22864No exploit | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · enterprise server · CWE-77 | High8.8 | — | 2.5% | Mar 23, 2021 |
36Monitor | CVE-2021-41599No exploit | Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code executiongithub · enterprise server · CWE-77 | High8.8 | — | 2.2% | Feb 17, 2022 |
- CVE-2024-020061This week
Unsafe Reflection in Github Enterprise Server leading to Command Injection
CriticalCVSS 9.8Proof of conceptEPSS 72%github · enterprise serverJan 16, 2024
- CVE-2024-050755Plan
Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
HighCVSS 8.8Proof of conceptEPSS 66%github · enterprise serverJan 16, 2024
- CVE-2024-948746Plan
An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed
CriticalCVSS 9.5Proof of conceptEPSS 26%github · enterprise serverOct 10, 2024
- CVE-2017-1836545Plan
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to e
CriticalCVSS 9.8WeaponizedEPSS 21%github · githubMar 28, 2019
- CVE-2024-498541Plan
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication
CriticalCVSS 10.0No exploitEPSS 3%github · enterprise serverMay 20, 2024
- CVE-2022-2472440Plan
Integer overflow in table parsing extension leads to heap memory corruption
CriticalCVSS 9.8No exploitEPSS 5%github · cmark-gfmMar 3, 2022
- CVE-2022-3932139Monitor
GitHub Actions Runner vulnerable to Docker Command Escaping
CriticalCVSS 9.9No exploitEPSS 2%github · runnerOct 25, 2022
- CVE-2020-1051639Monitor
Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member
CriticalCVSS 9.8No exploitEPSS 2%github · githubJun 3, 2020
- CVE-2022-4625539Monitor
Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE
CriticalCVSS 9.8No exploitEPSS 2%github · enterprise serverDec 14, 2022
- CVE-2024-2205139Monitor
CommonMarker Integer Overflow Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%github · cmark-gfmJan 4, 2024
- CVE-2022-2373939Monitor
Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv
CriticalCVSS 9.8No exploitEPSS 1%github · enterprise serverJan 17, 2023
- CVE-2021-2286939Monitor
Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group
CriticalCVSS 9.8No exploitEPSS 1%github · enterprise serverSep 24, 2021
- CVE-2015-1003139Monitor
purpleparrots 491-Project Highscore update.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%github · 491-projectJan 8, 2023
- CVE-2024-680038Monitor
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity
CriticalCVSS 9.5No exploitEPSS 2%github · enterprise serverAug 20, 2024
- CVE-2024-5230838Monitor
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
CriticalCVSS 9.6No exploitEPSS 1%github · cliNov 14, 2024
- CVE-2024-137437Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 3%github · enterprise serverFeb 13, 2024
- CVE-2024-135537Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 2%github · enterprise serverFeb 13, 2024
- CVE-2024-137837Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 2%github · enterprise serverFeb 13, 2024
- CVE-2024-135937Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 2%github · enterprise serverFeb 13, 2024
- CVE-2024-136937Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 2%github · enterprise serverFeb 13, 2024
- CVE-2024-137237Monitor
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
CriticalCVSS 9.1No exploitEPSS 2%github · enterprise serverFeb 13, 2024
- CVE-2020-1051836Monitor
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
HighCVSS 8.8No exploitEPSS 4%github · githubAug 27, 2020
- CVE-2020-1051936Monitor
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
HighCVSS 8.8No exploitEPSS 3%github · githubMar 3, 2021
- CVE-2021-2286436Monitor
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
HighCVSS 8.8No exploitEPSS 2%github · enterprise serverMar 23, 2021
- CVE-2021-4159936Monitor
Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code execution
HighCVSS 8.8No exploitEPSS 2%github · enterprise serverFeb 17, 2022