Enterprise Server
Vendor:
First CVE: Mar 23, 2021 · Active for 5 years
119
Total CVEs
More Total CVEs than 99% of tracked products
19.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Enterprise Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2021
5 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
CVE Severity & Scoring
Enterprise Server119 CVEs
52%
29%
15%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (2.5%)
Network116 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (89.9%)
High12 (10.1%)
Unknown0 (0.0%)
User Interaction
None92 (77.3%)
Unknown0 (0.0%)
Required27 (22.7%)
Privileges Required
Low58 (48.7%)
High26 (21.8%)
None35 (29.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (119 CVEs).
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0200CRITICAL An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contro | Jan 16, 2024 | 9.8 | 80 | NO | YES |
CVE-2024-0507HIGH An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Thi | Jan 16, 2024 | 8.8 | 63 | NO | NO |
CVE-2026-3854HIGH An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote | Mar 10, 2026 | 8.8 | 62 | NO | NO |
CVE-2024-9487CRITICAL An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauth | Oct 10, 2024 | 9.1 | 54 | NO | YES |
CVE-2026-9312HIGH A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services | May 27, 2026 | 8.2 | 40 | NO | NO |
CVE-2026-15343HIGH A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to | Jul 17, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-8034CRITICAL A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-6800CRITICAL An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed si | Aug 20, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-0573CRITICAL An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages | Feb 18, 2026 | 9.0 | 32 | NO | NO |
CVE-2024-4985CRITICAL An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions f | May 20, 2024 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (119 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (119 CVEs).
Media Mentions
Signals from CVEs in this product scope (119 CVEs).
Top CNAs Publishing CVEs For Enterprise Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.9.0 | 2 | 6.8 | 0.5% | 0 | 0 |
| 3.8.0 | 2 | 5.3 | 0.5% | 0 | 0 |
| 3.7.0 | 3 | 9.5 | 1.3% | 0 | 0 |
| 3.21.1 | 1 | 8.2 | 6.6% | 0 | 0 |
| 3.21.0 | 1 | 5.9 | 0.4% | 0 | 0 |
| 3.20.0 | 5 | 6.9 | 0.3% | 0 | 0 |
| 3.19.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 3.18.0 | 1 | 9.6 | 0.6% | 0 | 0 |
| 3.16.1 | 1 | 7.6 | 0.3% | 0 | 0 |
| 3.14.0 | 3 | 5.1 | 0.4% | 0 | 0 |
| 3.13.0 | 7 | 6.0 | 0.5% | 0 | 0 |
| 3.12.0 | 1 | 4.3 | 0.2% | 0 | 0 |
| 3.11.0 | 10 | 5.5 | 0.5% | 0 | 0 |
| 3.10.0 | 1 | 6.5 | 0.6% | 0 | 0 |