Vulnerabilidades em github
160 resultadosAnálise Vexday
GitHub apresenta 21 CVEs cadastradas na base, com 3 publicações nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma CVE está sob ataque ativo (KEV) e não há registros críticos (CVSS), reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), sugerindo exposição a negação de serviço e esgotamento de recursos em vez de comprometimento direto.
CVE-2024-10824MEDIUMAuthorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorized Internal Users to Access Secret Scanning Alert DataEPSS 0.3%CVE-2026-1999HIGHIncorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized merging of pull requestsEPSS 0.3%CVE-2023-6690LOWA race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphEPSS 0.3%CVE-2026-10585MEDIUMStored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A categoryEPSS 0.3%CVE-2025-8447HIGHIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only accessEPSS 0.3%CVE-2025-6600MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Search APIEPSS 0.3%CVE-2025-3246HIGHMarkdown math block sanitization bypass allows privilege escalation and unauthorized workflow triggersEPSS 0.3%CVE-2026-18730HIGHServer-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer tokenEPSS 0.3%CVE-2026-54163MEDIUMsecure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputEPSS 0.3%CVE-2025-6981MEDIUMIncorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only accessEPSS 0.3%CVE-2026-8106MEDIUMReflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential theftEPSS 0.3%CVE-2024-5815MEDIUMCross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repositoryEPSS 0.3%CVE-2018-25188HIGHWebiness Inventory 2.3 SQL Injection via WsModelGrid.phpEPSS 0.2%CVE-2025-13744HIGHImproper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTMLEPSS 0.2%CVE-2026-48529MEDIUMGitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusionEPSS 0.2%CVE-2023-6804MEDIUMImproper Privilege Management allows for arbitrary workflows to be runEPSS 0.2%CVE-2024-2748MEDIUMCSRF vulnerability was identified in GitHub Enterprise Server that allowed performing actions on behalf of a userEPSS 0.2%CVE-2026-2266HIGHImproper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting via task list content and enabled arbitrary HTML injectionEPSS 0.2%CVE-2023-46649MEDIUMRace Condition allows Administrative Access on Organization RepositoriesEPSS 0.2%CVE-2023-6803MEDIUMRace Condition allows Unauthorized Outside CollaboratorEPSS 0.2%