Vulnerabilidades en github
160 resultadosAnálisis Vexday
GitHub apresenta 21 CVEs cadastradas na base, com 3 publicações nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma CVE está sob ataque ativo (KEV) e não há registros críticos (CVSS), reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), sugerindo exposição a negação de serviço e esgotamento de recursos em vez de comprometimento direto.
CVE-2026-77912HIGHStored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipelineEPSS 0.4%CVE-2026-75101MEDIUMAuthorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collisionEPSS 0.4%CVE-2024-8263MEDIUMAn improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use ofEPSS 0.4%CVE-2026-15783MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suitesEPSS 0.4%CVE-2024-8810HIGHPrivilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessEPSS 0.4%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.4%CVE-2026-3306MEDIUMImproper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessEPSS 0.4%CVE-2024-1482HIGHImproper Authorization in GitHub Enterprise Server allowed unauthorized workflow execution EPSS 0.4%CVE-2024-6336MEDIUMSecurity misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureEPSS 0.4%CVE-2025-3124MEDIUMMissing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository namesEPSS 0.4%CVE-2026-9132MEDIUMMissing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpointEPSS 0.4%CVE-2026-6736MEDIUMAuthentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the configured external identity providerEPSS 0.4%CVE-2026-1355MEDIUMMissing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration ExportsEPSS 0.4%CVE-2026-3582MEDIUMIncorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scopeEPSS 0.4%CVE-2021-32638MEDIUMCodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedEPSS 0.4%CVE-2025-14046HIGHInsufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST RequestsEPSS 0.4%CVE-2024-10001HIGHCode Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message HandlingEPSS 0.4%CVE-2026-45033HIGHGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorEPSS 0.4%CVE-2024-8770MEDIUMA Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attacEPSS 0.4%CVE-2026-9106MEDIUMUI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screenEPSS 0.4%