Vulnerabilities > Github > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-46255 Path Traversal vulnerability in Github Enterprise Server 3.7.0
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution.
network
low complexity
github CWE-22
critical
9.8
2022-10-25 CVE-2022-39321 OS Command Injection vulnerability in Github Runner
GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow.
network
low complexity
github CWE-78
critical
9.9
2022-03-03 CVE-2022-24724 Integer Overflow or Wraparound vulnerability in multiple products
cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark.
network
low complexity
github fedoraproject CWE-190
critical
9.8
2021-09-24 CVE-2021-22869 Improper Authentication vulnerability in Github Enterprise Server
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to.
network
low complexity
github CWE-287
critical
9.8