github kayıtları
github üreticisine ait 158 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,6
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %81,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-863 Incorrect Authorization14
- CWE-20 Improper Input Validation13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')9
- CWE-269 Improper Privilege Management8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
158 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2024-0200Kavram kanıtı | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Kritik9,8 | — | %71,7 | 16 Oca 2024 |
55Planlayın | CVE-2024-0507Kavram kanıtı | Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Servergithub · enterprise server · CWE-20 | Yüksek8,8 | — | %65,8 | 16 Oca 2024 |
46Planlayın | CVE-2024-9487Kavram kanıtı | An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassedgithub · enterprise server · CWE-347 | Kritik9,5 | — | %25,6 | 10 Eki 2024 |
45Planlayın | CVE-2017-18365Silahlaştırılmış | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to egithub · github · CWE-502 | Kritik9,8 | — | %21,2 | 28 Mar 2019 |
41Planlayın | CVE-2024-4985İstismar yok | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication github · enterprise server · CWE-303 | Kritik10,0 | — | %2,6 | 20 May 2024 |
40Planlayın | CVE-2022-24724İstismar yok | Integer overflow in table parsing extension leads to heap memory corruptiongithub · cmark-gfm · CWE-190 | Kritik9,8 | — | %4,5 | 3 Mar 2022 |
39İzleyin | CVE-2022-39321İstismar yok | GitHub Actions Runner vulnerable to Docker Command Escapinggithub · runner · CWE-78 | Kritik9,9 | — | %1,6 | 25 Eki 2022 |
39İzleyin | CVE-2020-10516İstismar yok | Improper access control in GitHub Enterprise Server leading to privilege escalation of organization membergithub · github · CWE-285 | Kritik9,8 | — | %1,6 | 3 Haz 2020 |
39İzleyin | CVE-2022-46255İstismar yok | Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCEgithub · enterprise server · CWE-22 | Kritik9,8 | — | %1,5 | 14 Ara 2022 |
39İzleyin | CVE-2024-22051İstismar yok | CommonMarker Integer Overflow Vulnerabilitygithub · cmark-gfm · CWE-190 | Kritik9,8 | — | %1,5 | 4 Oca 2024 |
39İzleyin | CVE-2022-23739İstismar yok | Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-servgithub · enterprise server · CWE-863 | Kritik9,8 | — | %1,2 | 17 Oca 2023 |
39İzleyin | CVE-2021-22869İstismar yok | Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupgithub · enterprise server · CWE-668 | Kritik9,8 | — | %1,2 | 24 Eyl 2021 |
39İzleyin | CVE-2015-10031İstismar yok | purpleparrots 491-Project Highscore update.php sql injectiongithub · 491-project · CWE-89 | Kritik9,8 | — | %0,7 | 8 Oca 2023 |
38İzleyin | CVE-2024-6800İstismar yok | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identitygithub · enterprise server · CWE-347 | Kritik9,5 | — | %1,5 | 20 Ağu 2024 |
38İzleyin | CVE-2024-52308İstismar yok | Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computergithub · cli · CWE-77 | Kritik9,6 | — | %0,9 | 14 Kas 2024 |
37İzleyin | CVE-2024-1374İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,6 | 13 Şub 2024 |
37İzleyin | CVE-2024-1355İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,4 | 13 Şub 2024 |
37İzleyin | CVE-2024-1378İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,3 | 13 Şub 2024 |
37İzleyin | CVE-2024-1359İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,3 | 13 Şub 2024 |
37İzleyin | CVE-2024-1369İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,3 | 13 Şub 2024 |
37İzleyin | CVE-2024-1372İstismar yok | Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Consolegithub · enterprise server · CWE-20 | Kritik9,1 | — | %2,3 | 13 Şub 2024 |
36İzleyin | CVE-2020-10518İstismar yok | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | Yüksek8,8 | — | %3,7 | 27 Ağu 2020 |
36İzleyin | CVE-2020-10519İstismar yok | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · github · CWE-77 | Yüksek8,8 | — | %3,1 | 3 Mar 2021 |
36İzleyin | CVE-2021-22864İstismar yok | Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Servergithub · enterprise server · CWE-77 | Yüksek8,8 | — | %2,5 | 23 Mar 2021 |
36İzleyin | CVE-2021-41599İstismar yok | Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code executiongithub · enterprise server · CWE-77 | Yüksek8,8 | — | %2,2 | 17 Şub 2022 |
- CVE-2024-020061Bu hafta
Unsafe Reflection in Github Enterprise Server leading to Command Injection
KritikCVSS 9,8Kavram kanıtıEPSS %72github · enterprise server16 Oca 2024
- CVE-2024-050755Planlayın
Privilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
YüksekCVSS 8,8Kavram kanıtıEPSS %66github · enterprise server16 Oca 2024
- CVE-2024-948746Planlayın
An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed
KritikCVSS 9,5Kavram kanıtıEPSS %26github · enterprise server10 Eki 2024
- CVE-2017-1836545Planlayın
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to e
KritikCVSS 9,8SilahlaştırılmışEPSS %21github · github28 Mar 2019
- CVE-2024-498541Planlayın
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication
KritikCVSS 10,0İstismar yokEPSS %3github · enterprise server20 May 2024
- CVE-2022-2472440Planlayın
Integer overflow in table parsing extension leads to heap memory corruption
KritikCVSS 9,8İstismar yokEPSS %5github · cmark-gfm3 Mar 2022
- CVE-2022-3932139İzleyin
GitHub Actions Runner vulnerable to Docker Command Escaping
KritikCVSS 9,9İstismar yokEPSS %2github · runner25 Eki 2022
- CVE-2020-1051639İzleyin
Improper access control in GitHub Enterprise Server leading to privilege escalation of organization member
KritikCVSS 9,8İstismar yokEPSS %2github · github3 Haz 2020
- CVE-2022-4625539İzleyin
Improper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCE
KritikCVSS 9,8İstismar yokEPSS %2github · enterprise server14 Ara 2022
- CVE-2024-2205139İzleyin
CommonMarker Integer Overflow Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1github · cmark-gfm4 Oca 2024
- CVE-2022-2373939İzleyin
Incorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-serv
KritikCVSS 9,8İstismar yokEPSS %1github · enterprise server17 Oca 2023
- CVE-2021-2286939İzleyin
Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group
KritikCVSS 9,8İstismar yokEPSS %1github · enterprise server24 Eyl 2021
- CVE-2015-1003139İzleyin
purpleparrots 491-Project Highscore update.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1github · 491-project8 Oca 2023
- CVE-2024-680038İzleyin
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity
KritikCVSS 9,5İstismar yokEPSS %2github · enterprise server20 Ağu 2024
- CVE-2024-5230838İzleyin
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
KritikCVSS 9,6İstismar yokEPSS %1github · cli14 Kas 2024
- CVE-2024-137437İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %3github · enterprise server13 Şub 2024
- CVE-2024-135537İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %2github · enterprise server13 Şub 2024
- CVE-2024-137837İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %2github · enterprise server13 Şub 2024
- CVE-2024-135937İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %2github · enterprise server13 Şub 2024
- CVE-2024-136937İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %2github · enterprise server13 Şub 2024
- CVE-2024-137237İzleyin
Command injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement Console
KritikCVSS 9,1İstismar yokEPSS %2github · enterprise server13 Şub 2024
- CVE-2020-1051836İzleyin
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
YüksekCVSS 8,8İstismar yokEPSS %4github · github27 Ağu 2020
- CVE-2020-1051936İzleyin
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
YüksekCVSS 8,8İstismar yokEPSS %3github · github3 Mar 2021
- CVE-2021-2286436İzleyin
Unsafe configuration options in GitHub Pages leading to remote code execution on GitHub Enterprise Server
YüksekCVSS 8,8İstismar yokEPSS %2github · enterprise server23 Mar 2021
- CVE-2021-4159936İzleyin
Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code execution
YüksekCVSS 8,8İstismar yokEPSS %2github · enterprise server17 Şub 2022