Vulnerabilities in Github
160 resultsVexday analysis
GitHub apresenta postura baixa de risco com apenas 1 CVE registrado na base, nenhum explorado ativamente (KEV) e nenhuma vulnerabilidade crítica identificada. A fraqueza documentada (CWE-89 - SQL Injection) não está sendo explorada em campo, e a ausência de publicações recentes sugere que o risco não está em evolução ativa.
CVE-2022-23738MEDIUMIncomplete cache verification issue in GitHub Enterprise Server leading to exposure of private repo filesEPSS 0.7%CVE-2023-23763MEDIUMInformation disclosure in GitHub Enterprise Server leading to private repository leakageEPSS 0.7%CVE-2025-11578HIGHPre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege EscalationEPSS 0.7%CVE-2026-7541MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpointEPSS 0.7%CVE-2026-0573HIGHImproper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that allowed leaking of authorization token and enabled remote code executionEPSS 0.7%CVE-2025-11892HIGHDOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggersEPSS 0.7%CVE-2026-5921HIGHServer-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attackEPSS 0.6%CVE-2023-23762MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2023-46647HIGHImproper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation EPSS 0.6%CVE-2024-9539MEDIUMAn information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to EPSS 0.6%CVE-2026-15007MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configurationEPSS 0.6%CVE-2023-51379MEDIUMIncorrect Authorization for Issue Comments in GitHub Enterprise Server EPSS 0.6%CVE-2023-23765MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2024-1908MEDIUMImproper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege EscalationEPSS 0.6%CVE-2026-9312CRITICALServer-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpointEPSS 0.6%CVE-2023-23764MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2024-3470MEDIUMRepository administrator can bypass organization's ruleset using deploy keysEPSS 0.6%CVE-2022-23733—Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributesEPSS 0.6%CVE-2026-19311HIGHMissing Authorization in Execute Monitor API in OpenSearch Alerting PluginEPSS 0.6%CVE-2026-15343HIGHPath traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file pathsEPSS 0.6%