Vulnerabilities in github
151 resultsVexday analysis
GitHub apresenta 21 CVEs cadastradas na base, com 3 publicações nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma CVE está sob ataque ativo (KEV) e não há registros críticos (CVSS), reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), sugerindo exposição a negação de serviço e esgotamento de recursos em vez de comprometimento direto.
CVE-2024-8770MEDIUMA Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attacEPSS 0.4%CVE-2026-45033HIGHGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorEPSS 0.4%CVE-2024-10824MEDIUMAuthorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert DataEPSS 0.3%CVE-2023-6690LOWA race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphEPSS 0.3%CVE-2026-3306MEDIUMImproper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessEPSS 0.3%CVE-2025-8447HIGHIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only accessEPSS 0.3%CVE-2026-5512MEDIUMImproper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy APIEPSS 0.3%CVE-2026-1999HIGHIncorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requestsEPSS 0.3%CVE-2026-5845HIGHImproper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise ServerEPSS 0.3%CVE-2025-3246HIGHMarkdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggersEPSS 0.3%CVE-2025-6600MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search APIEPSS 0.3%CVE-2026-15783MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suitesEPSS 0.3%CVE-2026-3307MEDIUMAuthorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersEPSS 0.3%CVE-2026-6736MEDIUMAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity providerEPSS 0.3%CVE-2025-6981MEDIUMIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only accessEPSS 0.3%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.3%CVE-2026-9132MEDIUMMissing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpointEPSS 0.3%CVE-2024-5815MEDIUMCross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositoryEPSS 0.3%CVE-2026-3582MEDIUMIncorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scopeEPSS 0.2%CVE-2018-25188HIGHWebiness Inventory 2.3 SQL Injection via WsModelGrid.phpEPSS 0.2%