Vulnerabilidades em github
151 resultadosAnálise Vexday
GitHub apresenta 21 CVEs cadastradas na base, com 3 publicações nos últimos 90 dias, indicando atividade contínua de descoberta de vulnerabilidades. Nenhuma CVE está sob ataque ativo (KEV) e não há registros críticos (CVSS), reduzindo o risco imediato de exploração em massa. A fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), sugerindo exposição a negação de serviço e esgotamento de recursos em vez de comprometimento direto.
CVE-2022-46256HIGHPath traversal in GitHub Enterprise Server leading to remote code execution in GitHub PagesEPSS 1.9%CVE-2024-3646HIGHCommand injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.7%CVE-2024-1354HIGHCommand injection vulnerability was identified in GitHub Enterprise Server that allowed privilege escalation in the Mangement ConsoleEPSS 1.7%CVE-2022-23732—Path traversal in GitHub Enterprise Server management console leading to a bypass of CSRF protectionsEPSS 1.7%CVE-2022-39209HIGHUncontrolled Resource Consumption in cmark-gfmEPSS 1.7%CVE-2021-37700MEDIUMClipboard-based DOM-XSSEPSS 1.7%CVE-2024-2469HIGHRemote Code Execution in GitHub Enterprise Server Allowed Administrators to gain SSH access to the applianceEPSS 1.6%CVE-2020-10516—Improper access control in GitHub Enterprise Server leading to privilege escalation of organization memberEPSS 1.6%CVE-2025-23369HIGHImproper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper ValidationEPSS 1.6%CVE-2020-5238MEDIUMDenial of service in table parsing in cmark-gfmEPSS 1.6%CVE-2024-6800CRITICALAn XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identityEPSS 1.5%CVE-2022-46255CRITICALImproper Limitation of a Pathname to a Restricted Directory in GitHub Enterprise Server leading to RCEEPSS 1.4%CVE-2021-22865—Improper access control in GitHub Enterprise Server leading to unauthorized read access to private repository metadataEPSS 1.3%CVE-2025-3509HIGHPre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege EscalationEPSS 1.2%CVE-2022-23739CRITICALIncorrect authorization check in GitHub Enterprise Server leading to escalation of privileges in GraphQL API requests from GitHub Apps using scoped user-to-server tokensEPSS 1.2%CVE-2025-24362HIGHCodeQL GitHub Action failed workflow writes GitHub PAT to debug artifactsEPSS 1.2%CVE-2021-22869—Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupEPSS 1.2%CVE-2021-22867—Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerEPSS 1.2%CVE-2021-41598—UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to userEPSS 1.2%CVE-2022-23740HIGHImproper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code ExecutionEPSS 1.1%