Перейти к содержимому
Noroxi

Записи gogs

49 опубликованных записей вендора gogs.

Профиль для исследователя

Попали в KEV
1 · 2 %
С эксплойтом
2 · 4,1 %
Pre-auth RCE
6
С записью об исправлении
85,7 %
Медиана: публикация → KEV
33 дн.

Все записи

49 записей
  • CVE-2025-8110
    90Срочно

    File overwrite in file update API in Gogs

    ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 85 %

    gogs · gogs10 дек. 2025 г.

  • CVE-2022-2024
    68На этой неделе

    OS Command Injection in gogs/gogs

    КритическаяCVSS 9,8Эксплойта нетEPSS 98 %

    gogs · gogs25 февр. 2023 г.

  • CVE-2024-55947
    57В плане

    Gogs has a Path Traversal in file update API

    ВысокаяCVSS 8,7Proof of conceptEPSS 75 %

    gogs · gogs23 дек. 2024 г.

  • CVE-2022-0415
    55В плане

    Remote Command Execution in uploading repository file in gogs/gogs

    ВысокаяCVSS 8,8Proof of conceptEPSS 65 %

    gogs · gogs21 мар. 2022 г.

  • CVE-2024-39931
    55В плане

    Gogs through 0.13.0 allows deletion of internal files.

    КритическаяCVSS 9,9Эксплойта нетEPSS 53 %

    gogs · gogs4 июл. 2024 г.

  • CVE-2020-15867
    54В плане

    The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.

    ВысокаяCVSS 7,2Готовый эксплойтEPSS 87 %

    gogs · gogs16 окт. 2020 г.

  • CVE-2022-32174
    53В плане

    In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

    КритическаяCVSS 9,0Эксплойта нетEPSS 58 %

    gogs · gogs11 окт. 2022 г.

  • CVE-2018-18925
    48В плане

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    КритическаяCVSS 9,8Proof of conceptEPSS 31 %

    gogs · gogs4 нояб. 2018 г.

  • CVE-2024-39932
    44В плане

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

    КритическаяCVSS 9,9Эксплойта нетEPSS 17 %

    gogs · gogs4 июл. 2024 г.

  • CVE-2022-1993
    43В плане

    Path Traversal in gogs/gogs

    ВысокаяCVSS 8,1Эксплойта нетEPSS 36 %

    gogs · gogs9 июн. 2022 г.

  • CVE-2024-39930
    41В плане

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    КритическаяCVSS 9,9Proof of conceptEPSS 8 %

    gogs · gogs4 июл. 2024 г.

  • CVE-2024-44625
    40В плане

    Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

    ВысокаяCVSS 8,8Proof of conceptEPSS 17 %

    gogs · gogs15 нояб. 2024 г.

  • CVE-2022-1986
    40В плане

    OS Command Injection in gogs/gogs

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    gogs · gogs9 июн. 2022 г.

  • CVE-2022-1884
    40В плане

    Remote Command Execution in gogs/gogs

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    gogs · gogs15 нояб. 2024 г.

  • CVE-2019-14544
    39Наблюдать

    routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    gogs · gogs2 авг. 2019 г.

  • CVE-2024-56731
    39Наблюдать

    Gogs deletion of internal files allows remote command execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gogs · gogs24 июн. 2025 г.

  • CVE-2022-1992
    37Наблюдать

    Path Traversal in gogs/gogs

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    gogs · gogs9 июн. 2022 г.

  • CVE-2025-64111
    37Наблюдать

    Gogs's update .git/config file allows remote command execution

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    gogs · gogs6 февр. 2026 г.

  • CVE-2026-25921
    37Наблюдать

    Gogs: Cross-repository LFS object overwrite via missing content hash verification

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    gogs · gogs5 мар. 2026 г.

  • CVE-2021-32546
    36Наблюдать

    Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    gogs · gogs2 июн. 2022 г.

  • CVE-2022-0871
    36Наблюдать

    Missing Authorization in gogs/gogs

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    gogs · gogs11 мар. 2022 г.

  • CVE-2018-15192
    35Наблюдать

    An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

    ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %

    gitea · gitea7 авг. 2018 г.

  • CVE-2018-15193
    35Наблюдать

    A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    gogs · gogs7 авг. 2018 г.

  • CVE-2026-26194
    35Наблюдать

    Gogs: Release tag option injection in release deletion

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    gogs · gogs5 мар. 2026 г.

  • CVE-2018-16409
    34Наблюдать

    In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    gogs · gogs3 сент. 2018 г.