Vulnerabilidades em GitHub

160 resultados
Análise Vexday

Com 119 CVEs catalogadas, o GitHub apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, o cenário exige atenção: 13 vulnerabilidades são de severidade crítica e CVE-2024-0200 alcança EPSS de 0,7173 — valor que indica probabilidade elevada de exploração nos próximos 30 dias, tornando-a a principal prioridade de remediação no momento. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que sugere fragilidades recorrentes no controle de acesso que merecem revisão estrutural. As 11 CVEs surgidas nos últimos 90 dias indicam cadência ativa de descoberta, reforçando a necessidade de monitoramento contínuo mesmo na ausência de exploração confirmada.

CVE-2026-15007MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configurationEPSS 0.6%CVE-2023-51379MEDIUMIncorrect Authorization for Issue Comments in GitHub Enterprise Server EPSS 0.6%CVE-2023-23765MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2024-1908MEDIUMImproper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege EscalationEPSS 0.6%CVE-2023-23766MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2023-23764MEDIUMIncorrect comparison vulnerability in GitHub Enterprise Server leading to commit smugglingEPSS 0.6%CVE-2024-3470MEDIUMRepository administrator can bypass organization's ruleset using deploy keysEPSS 0.6%CVE-2022-23733Stored XSS vulnerability in GitHub Enterprise Server leading to injection of arbitrary attributesEPSS 0.6%CVE-2026-15343HIGHPath traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file pathsEPSS 0.6%CVE-2022-46257Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository namesEPSS 0.6%CVE-2022-46258MEDIUMIncorrect Authorization in GitHub Enterprise Server leads to Action Workflow modifications without Workflow ScopeEPSS 0.6%CVE-2024-5795HIGHDenial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionEPSS 0.6%CVE-2023-46646MEDIUMImproper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get EPSS 0.5%CVE-2026-19118HIGHRace condition vulnerability was identified in GitHub Enterprise Server that allowed remote code executionEPSS 0.5%CVE-2026-8034HIGHServer-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusionEPSS 0.5%CVE-2024-5817MEDIUMImproper authorization allows read access to issue content in GitHub Enterprise ServerEPSS 0.5%CVE-2023-6746HIGHSensitive Information in Log File in GitHub Enterprise Server EPSS 0.5%CVE-2026-76851HIGHServer-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal servicesEPSS 0.5%CVE-2024-5816MEDIUMImproper authorization allows persistent access in GitHub Enterprise ServerEPSS 0.5%CVE-2026-17556HIGHPath traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id headerEPSS 0.5%