13 Total CVEs
7 AI Analyzed
0 CISA KEV
10 Critical
All Vendors
Showing 1-13 of 13 CVEs
CVE-2026-1699
Analyzed
10
GitHub Multiple Products

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out...

2026-01-31
CVE-2026-0756
Analyzed
9.8
GitHub Multiple Products

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr...

2026-01-23
CVE-2025-66401
Analyzed
9.8
GitHub Multiple Products

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical...

2025-12-02
CVE-2025-65637
7.5
GitHub Multiple Products

A denial-of-service vulnerability exists in github

2025-12-06
CVE-2025-60021
Analyzed
9.8
GitHub Multiple Products

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to i...

2026-01-17
CVE-2025-59157
Analyzed
9.9
GitHub Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Reposit...

2026-01-06
CVE-2025-56005
Analyzed
9.8
GitHub Multiple Products

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the...

2026-01-21
CVE-2025-55322
7.3
GitHub Multiple Products

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network

2025-09-24
CVE-2025-54594
Analyzed
9.1
GitHub Multiple Products

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml Git...

2025-08-07
CVE-2025-54416
9.1
GitHub Multiple Products

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In version...

2025-07-28
CVE-2025-53773
7.8
GitHub Multiple Products

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2025-08-13
CVE-2025-53624
10
GitHub Multiple Products

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ver...

2025-07-10
CVE-2025-53546
9.1
GitHub Multiple Products

Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-commit.yml can be exploited by att...

2025-07-10