gogs kayıtları
gogs üreticisine ait 49 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2
- Silahlaştırılmış
- 2 · %4,1
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- 33 gün
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-862 Missing Authorization5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
49 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2025-8110Silahlaştırılmış | File overwrite in file update API in Gogsgogs · gogs · CWE-22 | Yüksek8,7 | KEV | %85,2 | 10 Ara 2025 |
68Bu hafta | CVE-2022-2024İstismar yok | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Kritik9,8 | — | %97,8 | 25 Şub 2023 |
57Planlayın | CVE-2024-55947Kavram kanıtı | Gogs has a Path Traversal in file update APIgogs · gogs · CWE-22 | Yüksek8,7 | — | %77,8 | 23 Ara 2024 |
55Planlayın | CVE-2022-0415Kavram kanıtı | Remote Command Execution in uploading repository file in gogs/gogsgogs · gogs · CWE-20 | Yüksek8,8 | — | %65,2 | 21 Mar 2022 |
55Planlayın | CVE-2024-39931İstismar yok | Gogs through 0.13.0 allows deletion of internal files.gogs · gogs · CWE-552 | Kritik9,9 | — | %52,7 | 4 Tem 2024 |
54Planlayın | CVE-2020-15867Silahlaştırılmış | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.gogs · gogs | Yüksek7,2 | — | %87,4 | 16 Eki 2020 |
53Planlayın | CVE-2022-32174İstismar yok | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.gogs · gogs · CWE-79 | Kritik9,0 | — | %58,0 | 11 Eki 2022 |
48Planlayın | CVE-2018-18925Kavram kanıtı | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Kritik9,8 | — | %31,1 | 4 Kas 2018 |
44Planlayın | CVE-2024-39932İstismar yok | Gogs through 0.13.0 allows argument injection during the previewing of changes.gogs · gogs · CWE-94 | Kritik9,9 | — | %17,3 | 4 Tem 2024 |
43Planlayın | CVE-2022-1993İstismar yok | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | Yüksek8,1 | — | %36,3 | 9 Haz 2022 |
41Planlayın | CVE-2024-39930Kavram kanıtı | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.gogs · gogs · CWE-88 | Kritik9,9 | — | %7,7 | 4 Tem 2024 |
40Planlayın | CVE-2024-44625Kavram kanıtı | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.gogs · gogs · CWE-22 | Yüksek8,8 | — | %16,5 | 15 Kas 2024 |
40Planlayın | CVE-2022-1986İstismar yok | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Kritik9,8 | — | %4,5 | 9 Haz 2022 |
40Planlayın | CVE-2022-1884İstismar yok | Remote Command Execution in gogs/gogsgogs · gogs · CWE-78 | Kritik9,8 | — | %1,8 | 15 Kas 2024 |
39İzleyin | CVE-2019-14544İstismar yok | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.gogs · gogs · CWE-862 | Kritik9,8 | — | %1,5 | 2 Ağu 2019 |
39İzleyin | CVE-2024-56731İstismar yok | Gogs deletion of internal files allows remote command executiongogs · gogs · CWE-552 | Kritik9,8 | — | %1,2 | 24 Haz 2025 |
37İzleyin | CVE-2022-1992İstismar yok | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | Kritik9,1 | — | %2,3 | 9 Haz 2022 |
37İzleyin | CVE-2025-64111İstismar yok | Gogs's update .git/config file allows remote command executiongogs · gogs · CWE-78 | Kritik9,3 | — | %1,3 | 6 Şub 2026 |
37İzleyin | CVE-2026-25921İstismar yok | Gogs: Cross-repository LFS object overwrite via missing content hash verificationgogs · gogs · CWE-345 | Kritik9,3 | — | %0,3 | 5 Mar 2026 |
36İzleyin | CVE-2021-32546İstismar yok | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.gogs · gogs | Yüksek8,8 | — | %2,1 | 2 Haz 2022 |
36İzleyin | CVE-2022-0871İstismar yok | Missing Authorization in gogs/gogsgogs · gogs · CWE-862 | Kritik9,1 | — | %1,2 | 11 Mar 2022 |
35İzleyin | CVE-2018-15192İstismar yok | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.gitea · gitea · CWE-918 | Yüksek8,6 | — | %2,1 | 7 Ağu 2018 |
35İzleyin | CVE-2018-15193İstismar yok | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / ligogs · gogs · CWE-352 | Yüksek8,8 | — | %0,8 | 7 Ağu 2018 |
35İzleyin | CVE-2026-26194İstismar yok | Gogs: Release tag option injection in release deletiongogs · gogs · CWE-88 | Yüksek8,8 | — | %0,5 | 5 Mar 2026 |
34İzleyin | CVE-2018-16409İstismar yok | In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.gogs · gogs · CWE-918 | Yüksek8,6 | — | %1,3 | 3 Eyl 2018 |
- CVE-2025-811090Hemen
File overwrite in file update API in Gogs
YüksekCVSS 8,7KEVSilahlaştırılmışEPSS %85gogs · gogs10 Ara 2025
- CVE-2022-202468Bu hafta
OS Command Injection in gogs/gogs
KritikCVSS 9,8İstismar yokEPSS %98gogs · gogs25 Şub 2023
- CVE-2024-5594757Planlayın
Gogs has a Path Traversal in file update API
YüksekCVSS 8,7Kavram kanıtıEPSS %78gogs · gogs23 Ara 2024
- CVE-2022-041555Planlayın
Remote Command Execution in uploading repository file in gogs/gogs
YüksekCVSS 8,8Kavram kanıtıEPSS %65gogs · gogs21 Mar 2022
- CVE-2024-3993155Planlayın
Gogs through 0.13.0 allows deletion of internal files.
KritikCVSS 9,9İstismar yokEPSS %53gogs · gogs4 Tem 2024
- CVE-2020-1586754Planlayın
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.
YüksekCVSS 7,2SilahlaştırılmışEPSS %87gogs · gogs16 Eki 2020
- CVE-2022-3217453Planlayın
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
KritikCVSS 9,0İstismar yokEPSS %58gogs · gogs11 Eki 2022
- CVE-2018-1892548Planlayın
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
KritikCVSS 9,8Kavram kanıtıEPSS %31gogs · gogs4 Kas 2018
- CVE-2024-3993244Planlayın
Gogs through 0.13.0 allows argument injection during the previewing of changes.
KritikCVSS 9,9İstismar yokEPSS %17gogs · gogs4 Tem 2024
- CVE-2022-199343Planlayın
Path Traversal in gogs/gogs
YüksekCVSS 8,1İstismar yokEPSS %36gogs · gogs9 Haz 2022
- CVE-2024-3993041Planlayın
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.
KritikCVSS 9,9Kavram kanıtıEPSS %8gogs · gogs4 Tem 2024
- CVE-2024-4462540Planlayın
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
YüksekCVSS 8,8Kavram kanıtıEPSS %17gogs · gogs15 Kas 2024
- CVE-2022-198640Planlayın
OS Command Injection in gogs/gogs
KritikCVSS 9,8İstismar yokEPSS %4gogs · gogs9 Haz 2022
- CVE-2022-188440Planlayın
Remote Command Execution in gogs/gogs
KritikCVSS 9,8İstismar yokEPSS %2gogs · gogs15 Kas 2024
- CVE-2019-1454439İzleyin
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
KritikCVSS 9,8İstismar yokEPSS %2gogs · gogs2 Ağu 2019
- CVE-2024-5673139İzleyin
Gogs deletion of internal files allows remote command execution
KritikCVSS 9,8İstismar yokEPSS %1gogs · gogs24 Haz 2025
- CVE-2022-199237İzleyin
Path Traversal in gogs/gogs
KritikCVSS 9,1İstismar yokEPSS %2gogs · gogs9 Haz 2022
- CVE-2025-6411137İzleyin
Gogs's update .git/config file allows remote command execution
KritikCVSS 9,3İstismar yokEPSS %1gogs · gogs6 Şub 2026
- CVE-2026-2592137İzleyin
Gogs: Cross-repository LFS object overwrite via missing content hash verification
KritikCVSS 9,3İstismar yokEPSS %0gogs · gogs5 Mar 2026
- CVE-2021-3254636İzleyin
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.
YüksekCVSS 8,8İstismar yokEPSS %2gogs · gogs2 Haz 2022
- CVE-2022-087136İzleyin
Missing Authorization in gogs/gogs
KritikCVSS 9,1İstismar yokEPSS %1gogs · gogs11 Mar 2022
- CVE-2018-1519235İzleyin
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
YüksekCVSS 8,6İstismar yokEPSS %2gitea · gitea7 Ağu 2018
- CVE-2018-1519335İzleyin
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li
YüksekCVSS 8,8İstismar yokEPSS %1gogs · gogs7 Ağu 2018
- CVE-2026-2619435İzleyin
Gogs: Release tag option injection in release deletion
YüksekCVSS 8,8İstismar yokEPSS %1gogs · gogs5 Mar 2026
- CVE-2018-1640934İzleyin
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
YüksekCVSS 8,6İstismar yokEPSS %1gogs · gogs3 Eyl 2018