CVE-2025-14046
- EPSS 0.04%
- Veröffentlicht 11.12.2025 17:52:05
- Zuletzt bearbeitet 19.12.2025 19:47:36
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shado...
CVE-2025-11578
- EPSS 0.1%
- Veröffentlicht 10.11.2025 22:44:33
- Zuletzt bearbeitet 08.12.2025 18:22:46
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a mal...
CVE-2025-11892
- EPSS 0.05%
- Veröffentlicht 10.11.2025 22:43:41
- Zuletzt bearbeitet 08.12.2025 18:18:51
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues search label filter that could lead to privilege escalation and unauthorized workflow triggers. Success...
CVE-2025-8447
- EPSS 0.03%
- Veröffentlicht 26.08.2025 01:42:37
- Zuletzt bearbeitet 03.09.2025 17:42:50
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this...
CVE-2025-6981
- EPSS 0.03%
- Veröffentlicht 15.07.2025 20:44:30
- Zuletzt bearbeitet 27.08.2025 14:41:04
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private previe...
CVE-2025-6600
- EPSS 0.02%
- Veröffentlicht 01.07.2025 18:56:45
- Zuletzt bearbeitet 05.09.2025 14:59:47
An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-ser...
CVE-2025-3246
- EPSS 0.03%
- Veröffentlicht 17.04.2025 22:50:22
- Zuletzt bearbeitet 05.09.2025 15:00:02
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server ins...
CVE-2025-3509
- EPSS 0.7%
- Veröffentlicht 17.04.2025 22:50:18
- Zuletzt bearbeitet 05.09.2025 14:59:50
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromis...
CVE-2025-3124
- EPSS 0.04%
- Veröffentlicht 17.04.2025 22:50:14
- Zuletzt bearbeitet 05.09.2025 15:00:04
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Securi...
CVE-2024-10001
- EPSS 0.16%
- Veröffentlicht 29.01.2025 19:15:18
- Zuletzt bearbeitet 05.09.2025 15:00:06
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive d...