Vulnerabilidades en github
160 resultadosAnálisis Vexday
GitHub apresenta 21 CVEs cadastradas na base, com 3 publicações nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma CVE está sob ataque ativo (KEV) e não há registros críticos (CVSS), reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), sugerindo exposição a negação de serviço e esgotamento de recursos em vez de comprometimento direto.
CVE-2023-22381MEDIUMCode injection in GitHub Enterprise Server leading to arbitrary environment variables in GitHub ActionsEPSS 0.8%CVE-2021-22862—Improper access control in GitHub Enterprise Server leading to the disclosure of Actions secrets to forksEPSS 0.8%CVE-2026-76851HIGHServer-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal servicesEPSS 0.8%CVE-2023-6847HIGHImproper Authentication in GitHub Enterprise Server leading to Authentication Bypass for Public Repository DataEPSS 0.8%CVE-2026-17556HIGHPath traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id headerEPSS 0.8%CVE-2023-46645MEDIUMPath traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteEPSS 0.8%CVE-2024-25129LOWLimited data exfiltration in CodeQL CLIEPSS 0.8%CVE-2026-47427HIGHGitHub MCP Server: Nil Pointer Dereference DoS in completion/complete HandlerEPSS 0.8%CVE-2024-1082MEDIUMPath traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact uploadEPSS 0.8%CVE-2026-15996MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parametersEPSS 0.8%CVE-2023-46648HIGHInsufficient Entropy in GitHub Enterprise Server Management Console Invitation TokenEPSS 0.7%CVE-2023-23766MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.7%CVE-2026-4296HIGHIncorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassEPSS 0.7%CVE-2023-22485MEDIUMcmark-gfm out-of-bounds read in validate_protocolEPSS 0.7%CVE-2023-6802HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.7%CVE-2022-23737MEDIUMImproper Privilege Management in GitHub Enterprise Server leading to page creation and deletionEPSS 0.7%CVE-2024-6337MEDIUMIncorrect Authorization allows read access to issues in GitHub Enterprise ServerEPSS 0.7%CVE-2026-8606HIGHServer-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL EndpointEPSS 0.7%CVE-2023-37463MEDIUMQuadratic complexity bugs may lead to a denial of serviceEPSS 0.7%CVE-2023-22380MEDIUMPath traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteEPSS 0.7%