Записи gogs
49 опубликованных записей вендора gogs.
Профиль для исследователя
- Попали в KEV
- 1 · 2 %
- С эксплойтом
- 2 · 4,1 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- 33 дн.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-862 Missing Authorization5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2025-8110Готовый эксплойт | File overwrite in file update API in Gogsgogs · gogs · CWE-22 | Высокая8,7 | KEV | 85,2 % | 10 дек. 2025 г. |
68На этой неделе | CVE-2022-2024Эксплойта нет | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Критическая9,8 | — | 97,8 % | 25 февр. 2023 г. |
57В плане | CVE-2024-55947Proof of concept | Gogs has a Path Traversal in file update APIgogs · gogs · CWE-22 | Высокая8,7 | — | 75,2 % | 23 дек. 2024 г. |
55В плане | CVE-2022-0415Proof of concept | Remote Command Execution in uploading repository file in gogs/gogsgogs · gogs · CWE-20 | Высокая8,8 | — | 65,2 % | 21 мар. 2022 г. |
55В плане | CVE-2024-39931Эксплойта нет | Gogs through 0.13.0 allows deletion of internal files.gogs · gogs · CWE-552 | Критическая9,9 | — | 52,7 % | 4 июл. 2024 г. |
54В плане | CVE-2020-15867Готовый эксплойт | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.gogs · gogs | Высокая7,2 | — | 87,4 % | 16 окт. 2020 г. |
53В плане | CVE-2022-32174Эксплойта нет | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.gogs · gogs · CWE-79 | Критическая9,0 | — | 58,0 % | 11 окт. 2022 г. |
48В плане | CVE-2018-18925Proof of concept | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Критическая9,8 | — | 31,1 % | 4 нояб. 2018 г. |
44В плане | CVE-2024-39932Эксплойта нет | Gogs through 0.13.0 allows argument injection during the previewing of changes.gogs · gogs · CWE-94 | Критическая9,9 | — | 17,3 % | 4 июл. 2024 г. |
43В плане | CVE-2022-1993Эксплойта нет | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | Высокая8,1 | — | 36,3 % | 9 июн. 2022 г. |
41В плане | CVE-2024-39930Proof of concept | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.gogs · gogs · CWE-88 | Критическая9,9 | — | 7,7 % | 4 июл. 2024 г. |
40В плане | CVE-2024-44625Proof of concept | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.gogs · gogs · CWE-22 | Высокая8,8 | — | 16,5 % | 15 нояб. 2024 г. |
40В плане | CVE-2022-1986Эксплойта нет | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Критическая9,8 | — | 4,5 % | 9 июн. 2022 г. |
40В плане | CVE-2022-1884Эксплойта нет | Remote Command Execution in gogs/gogsgogs · gogs · CWE-78 | Критическая9,8 | — | 1,8 % | 15 нояб. 2024 г. |
39Наблюдать | CVE-2019-14544Эксплойта нет | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.gogs · gogs · CWE-862 | Критическая9,8 | — | 1,5 % | 2 авг. 2019 г. |
39Наблюдать | CVE-2024-56731Эксплойта нет | Gogs deletion of internal files allows remote command executiongogs · gogs · CWE-552 | Критическая9,8 | — | 1,2 % | 24 июн. 2025 г. |
37Наблюдать | CVE-2022-1992Эксплойта нет | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | Критическая9,1 | — | 2,3 % | 9 июн. 2022 г. |
37Наблюдать | CVE-2025-64111Эксплойта нет | Gogs's update .git/config file allows remote command executiongogs · gogs · CWE-78 | Критическая9,3 | — | 1,3 % | 6 февр. 2026 г. |
37Наблюдать | CVE-2026-25921Эксплойта нет | Gogs: Cross-repository LFS object overwrite via missing content hash verificationgogs · gogs · CWE-345 | Критическая9,3 | — | 0,3 % | 5 мар. 2026 г. |
36Наблюдать | CVE-2021-32546Эксплойта нет | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.gogs · gogs | Высокая8,8 | — | 2,1 % | 2 июн. 2022 г. |
36Наблюдать | CVE-2022-0871Эксплойта нет | Missing Authorization in gogs/gogsgogs · gogs · CWE-862 | Критическая9,1 | — | 1,2 % | 11 мар. 2022 г. |
35Наблюдать | CVE-2018-15192Эксплойта нет | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.gitea · gitea · CWE-918 | Высокая8,6 | — | 2,1 % | 7 авг. 2018 г. |
35Наблюдать | CVE-2018-15193Эксплойта нет | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / ligogs · gogs · CWE-352 | Высокая8,8 | — | 0,8 % | 7 авг. 2018 г. |
35Наблюдать | CVE-2026-26194Эксплойта нет | Gogs: Release tag option injection in release deletiongogs · gogs · CWE-88 | Высокая8,8 | — | 0,5 % | 5 мар. 2026 г. |
34Наблюдать | CVE-2018-16409Эксплойта нет | In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.gogs · gogs · CWE-918 | Высокая8,6 | — | 1,3 % | 3 сент. 2018 г. |
- CVE-2025-811090Срочно
File overwrite in file update API in Gogs
ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 85 %gogs · gogs10 дек. 2025 г.
- CVE-2022-202468На этой неделе
OS Command Injection in gogs/gogs
КритическаяCVSS 9,8Эксплойта нетEPSS 98 %gogs · gogs25 февр. 2023 г.
- CVE-2024-5594757В плане
Gogs has a Path Traversal in file update API
ВысокаяCVSS 8,7Proof of conceptEPSS 75 %gogs · gogs23 дек. 2024 г.
- CVE-2022-041555В плане
Remote Command Execution in uploading repository file in gogs/gogs
ВысокаяCVSS 8,8Proof of conceptEPSS 65 %gogs · gogs21 мар. 2022 г.
- CVE-2024-3993155В плане
Gogs through 0.13.0 allows deletion of internal files.
КритическаяCVSS 9,9Эксплойта нетEPSS 53 %gogs · gogs4 июл. 2024 г.
- CVE-2020-1586754В плане
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.
ВысокаяCVSS 7,2Готовый эксплойтEPSS 87 %gogs · gogs16 окт. 2020 г.
- CVE-2022-3217453В плане
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
КритическаяCVSS 9,0Эксплойта нетEPSS 58 %gogs · gogs11 окт. 2022 г.
- CVE-2018-1892548В плане
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
КритическаяCVSS 9,8Proof of conceptEPSS 31 %gogs · gogs4 нояб. 2018 г.
- CVE-2024-3993244В плане
Gogs through 0.13.0 allows argument injection during the previewing of changes.
КритическаяCVSS 9,9Эксплойта нетEPSS 17 %gogs · gogs4 июл. 2024 г.
- CVE-2022-199343В плане
Path Traversal in gogs/gogs
ВысокаяCVSS 8,1Эксплойта нетEPSS 36 %gogs · gogs9 июн. 2022 г.
- CVE-2024-3993041В плане
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.
КритическаяCVSS 9,9Proof of conceptEPSS 8 %gogs · gogs4 июл. 2024 г.
- CVE-2024-4462540В плане
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %gogs · gogs15 нояб. 2024 г.
- CVE-2022-198640В плане
OS Command Injection in gogs/gogs
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gogs · gogs9 июн. 2022 г.
- CVE-2022-188440В плане
Remote Command Execution in gogs/gogs
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gogs · gogs15 нояб. 2024 г.
- CVE-2019-1454439Наблюдать
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gogs · gogs2 авг. 2019 г.
- CVE-2024-5673139Наблюдать
Gogs deletion of internal files allows remote command execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gogs · gogs24 июн. 2025 г.
- CVE-2022-199237Наблюдать
Path Traversal in gogs/gogs
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %gogs · gogs9 июн. 2022 г.
- CVE-2025-6411137Наблюдать
Gogs's update .git/config file allows remote command execution
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %gogs · gogs6 февр. 2026 г.
- CVE-2026-2592137Наблюдать
Gogs: Cross-repository LFS object overwrite via missing content hash verification
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %gogs · gogs5 мар. 2026 г.
- CVE-2021-3254636Наблюдать
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %gogs · gogs2 июн. 2022 г.
- CVE-2022-087136Наблюдать
Missing Authorization in gogs/gogs
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %gogs · gogs11 мар. 2022 г.
- CVE-2018-1519235Наблюдать
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %gitea · gitea7 авг. 2018 г.
- CVE-2018-1519335Наблюдать
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gogs · gogs7 авг. 2018 г.
- CVE-2026-2619435Наблюдать
Gogs: Release tag option injection in release deletion
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gogs · gogs5 мар. 2026 г.
- CVE-2018-1640934Наблюдать
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %gogs · gogs3 сент. 2018 г.