ahacker1
24 kredili kayıt · son 12 ayda 11 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
29İzleyin | CVE-2026-77912İstismar yok | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipelinegithub · enterprise server · CWE-79 | Yüksek7,4 | — | %0,5 | 22 Eyl 2026 |
30İzleyin | CVE-2026-19118İstismar yok | Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code executiongithub · enterprise server · CWE-367 | Yüksek7,7 | — | %0,5 | 1 Eyl 2026 |
21İzleyin | CVE-2026-14340İstismar yok | An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesgithub · enterprise server · CWE-863 | Orta5,3 | — | %0,4 | 1 Tem 2026 |
36İzleyin | CVE-2026-9312İstismar yok | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpointgithub · enterprise server · CWE-918 | Kritik9,2 | — | %0,6 | 26 May 2026 |
28İzleyin | CVE-2026-5845İstismar yok | Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Servergithub · enterprise server · CWE-639 | Yüksek7,2 | — | %0,5 | 21 Nis 2026 |
21İzleyin | CVE-2026-5512İstismar yok | Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy APIgithub · enterprise server · CWE-201 | Orta5,3 | — | %0,5 | 21 Nis 2026 |
30İzleyin | CVE-2026-4296İstismar yok | Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassgithub · enterprise server · CWE-185 | Yüksek7,5 | — | %0,7 | 21 Nis 2026 |
21İzleyin | CVE-2026-3307İstismar yok | Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersgithub · enterprise server · CWE-639 | Orta5,3 | — | %0,5 | 21 Nis 2026 |
21İzleyin | CVE-2026-3306Kavram kanıtı | Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessgithub · enterprise server · CWE-639 | Orta5,3 | — | %0,4 | 10 Mar 2026 |
28İzleyin | CVE-2026-1999Kavram kanıtı | Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requestsgithub · enterprise server · CWE-863 | Yüksek7,1 | — | %0,3 | 18 Şub 2026 |
24İzleyin | CVE-2026-1355İstismar yok | Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exportsgithub · enterprise server · CWE-862 | Orta6,0 | — | %0,4 | 18 Şub 2026 |
34İzleyin | CVE-2024-8810İstismar yok | Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessgithub · enterprise server · CWE-269 | Yüksek8,7 | — | %0,4 | 7 Kas 2024 |
21İzleyin | CVE-2024-7711İstismar yok | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, angithub · enterprise server · CWE-863 | Orta5,3 | — | %0,5 | 20 Ağu 2024 |
38İzleyin | CVE-2024-6800İstismar yok | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identitygithub · enterprise server · CWE-347 | Kritik9,5 | — | %1,5 | 20 Ağu 2024 |
25İzleyin | CVE-2024-6395İstismar yok | GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keysgithub · enterprise server · CWE-200 | Orta6,3 | — | %0,5 | 16 Tem 2024 |
23İzleyin | CVE-2024-5817İstismar yok | Improper authorization allows read access to issue content in GitHub Enterprise Servergithub · enterprise server · CWE-863 | Orta5,9 | — | %0,5 | 16 Tem 2024 |
27İzleyin | CVE-2024-5816İstismar yok | Improper authorization allows persistent access in GitHub Enterprise Servergithub · enterprise server · CWE-863 | Orta6,9 | — | %0,5 | 16 Tem 2024 |
27İzleyin | CVE-2024-5815İstismar yok | Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositorygithub · enterprise server · CWE-352 | Orta6,8 | — | %0,3 | 16 Tem 2024 |
26İzleyin | CVE-2024-1908İstismar yok | Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalationgithub · enterprise server · CWE-269 | Orta6,5 | — | %0,6 | 20 Mar 2024 |
26İzleyin | CVE-2024-1482İstismar yok | Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow executiongithub · enterprise server · CWE-863 | Orta6,5 | — | %0,4 | 14 Şub 2024 |
30İzleyin | CVE-2023-6847İstismar yok | Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Datagithub · enterprise server · CWE-287 | Yüksek7,5 | — | %0,8 | 21 Ara 2023 |
21İzleyin | CVE-2023-46646İstismar yok | Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get github · enterprise server · CWE-639 | Orta5,3 | — | %0,5 | 21 Ara 2023 |
39İzleyin | CVE-2022-23739İstismar yok | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-servgithub · enterprise server · CWE-863 | Kritik9,8 | — | %1,2 | 17 Oca 2023 |
22İzleyin | CVE-2022-23738İstismar yok | Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo filesgithub · enterprise server · CWE-200 | Orta5,7 | — | %0,7 | 1 Kas 2022 |
- CVE-2026-7791229İzleyin
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
YüksekCVSS 7,4İstismar yokEPSS %0github · enterprise server22 Eyl 2026
- CVE-2026-1911830İzleyin
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
YüksekCVSS 7,7İstismar yokEPSS %1github · enterprise server1 Eyl 2026
- CVE-2026-1434021İzleyin
An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories
OrtaCVSS 5,3İstismar yokEPSS %0github · enterprise server1 Tem 2026
- CVE-2026-931236İzleyin
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
KritikCVSS 9,2İstismar yokEPSS %1github · enterprise server26 May 2026
- CVE-2026-584528İzleyin
Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
YüksekCVSS 7,2İstismar yokEPSS %0github · enterprise server21 Nis 2026
- CVE-2026-551221İzleyin
Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API
OrtaCVSS 5,3İstismar yokEPSS %0github · enterprise server21 Nis 2026
- CVE-2026-429630İzleyin
Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
YüksekCVSS 7,5İstismar yokEPSS %1github · enterprise server21 Nis 2026
- CVE-2026-330721İzleyin
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
OrtaCVSS 5,3İstismar yokEPSS %0github · enterprise server21 Nis 2026
- CVE-2026-330621İzleyin
Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access
OrtaCVSS 5,3Kavram kanıtıEPSS %0github · enterprise server10 Mar 2026
- CVE-2026-199928İzleyin
Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requests
YüksekCVSS 7,1Kavram kanıtıEPSS %0github · enterprise server18 Şub 2026
- CVE-2026-135524İzleyin
Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports
OrtaCVSS 6,0İstismar yokEPSS %0github · enterprise server18 Şub 2026
- CVE-2024-881034İzleyin
Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write access
YüksekCVSS 8,7İstismar yokEPSS %0github · enterprise server7 Kas 2024
- CVE-2024-771121İzleyin
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, an
OrtaCVSS 5,3İstismar yokEPSS %0github · enterprise server20 Ağu 2024
- CVE-2024-680038İzleyin
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity
KritikCVSS 9,5İstismar yokEPSS %2github · enterprise server20 Ağu 2024
- CVE-2024-639525İzleyin
GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys
OrtaCVSS 6,3İstismar yokEPSS %0github · enterprise server16 Tem 2024
- CVE-2024-581723İzleyin
Improper authorization allows read access to issue content in GitHub Enterprise Server
OrtaCVSS 5,9İstismar yokEPSS %1github · enterprise server16 Tem 2024
- CVE-2024-581627İzleyin
Improper authorization allows persistent access in GitHub Enterprise Server
OrtaCVSS 6,9İstismar yokEPSS %1github · enterprise server16 Tem 2024
- CVE-2024-581527İzleyin
Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository
OrtaCVSS 6,8İstismar yokEPSS %0github · enterprise server16 Tem 2024
- CVE-2024-190826İzleyin
Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege Escalation
OrtaCVSS 6,5İstismar yokEPSS %1github · enterprise server20 Mar 2024
- CVE-2024-148226İzleyin
Improper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution
OrtaCVSS 6,5İstismar yokEPSS %0github · enterprise server14 Şub 2024
- CVE-2023-684730İzleyin
Improper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository Data
YüksekCVSS 7,5İstismar yokEPSS %1github · enterprise server21 Ara 2023
- CVE-2023-4664621İzleyin
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get
OrtaCVSS 5,3İstismar yokEPSS %1github · enterprise server21 Ara 2023
- CVE-2022-2373939İzleyin
Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv
KritikCVSS 9,8İstismar yokEPSS %1github · enterprise server17 Oca 2023
- CVE-2022-2373822İzleyin
Incomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo files
OrtaCVSS 5,7İstismar yokEPSS %1github · enterprise server1 Kas 2022