GitHub, Inc.
First CVE: Sep 30, 2019Active for: 7 years
17,518
CVEs Published
More CVEs Published than 100% of tracked CNAs
2189.8
Avg CVEs / Year
More Avg CVEs / Year than 99% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 81% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by GitHub, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2019
6 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by GitHub, Inc. as a CNA, regardless of affected vendor or product.
17,518 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42208CRITICAL LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key chec | May 8, 2026 | 9.8 | 99 | YES | YES |
CVE-2026-33017CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building | Mar 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-68613HIGH n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera | Dec 19, 2025 | 8.8 | 99 | YES | YES |
CVE-2025-32432CRITICAL Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, | Apr 25, 2025 | 10.0 | 99 | YES | YES |
CVE-2025-24893CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to | Feb 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2022-46169CRITICAL Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu | Dec 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2026-42271HIGH LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server befo | May 8, 2026 | 8.8 | 98 | YES | YES |
CVE-2026-39987CRITICAL marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowi | Apr 9, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-64328HIGH FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrat | Nov 7, 2025 | 7.2 | 98 | YES | YES |
CVE-2025-57819CRITICAL FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti | Aug 28, 2025 | 9.8 | 98 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA17,518 CVEs
43%
40%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalNoneUnknown
Attack Vector
Local1,776 (10.1%)
Network15,504 (88.5%)
Unknown2 (0.0%)
Physical52 (0.3%)
Adjacent Network179 (1.0%)
Attack Complexity
Low16,016 (91.4%)
High1,500 (8.6%)
Unknown2 (0.0%)
User Interaction
None12,840 (73.3%)
Unknown2 (0.0%)
Required4,400 (25.1%)
Privileges Required
Low6,356 (36.3%)
High1,208 (6.9%)
None9,952 (56.8%)
Unknown2 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (17518 CVEs).
CISA KEV
36 CVEs
0.2% of CVEs· 81st percentile
Metasploit
77 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
382 CVEs
2.2% of CVEs· 86th percentile
ExploitDB
112 CVEs
0.6% of CVEs· 79th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by GitHub, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by GitHub, Inc. as a CNA — matched by CVE ID, not by organization name.