Enterprise Server

Vendor:

First CVE: Mar 23, 2021 · Active for 5 years

119
Total CVEs
More Total CVEs than 99% of tracked products
19.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Enterprise Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2021
5 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

CVE Severity & Scoring

Enterprise Server119 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (2.5%)
Network116 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (89.9%)
High12 (10.1%)
Unknown0 (0.0%)
User Interaction
None92 (77.3%)
Unknown0 (0.0%)
Required27 (22.7%)
Privileges Required
Low58 (48.7%)
High26 (21.8%)
None35 (29.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (119 CVEs).

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-contro
Jan 16, 20249.880NOYES
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. Thi
Jan 16, 20248.863NONO
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote
Mar 10, 20268.862NONO
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauth
Oct 10, 20249.154NOYES
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services
May 27, 20268.240NONO
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to
Jul 17, 20268.636NONO
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting
May 7, 20269.836NONO
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed si
Aug 20, 20249.833NONO
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages
Feb 18, 20269.032NONO
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions f
May 20, 20249.832NONO

Exploit Exposure

Signals from CVEs in this product scope (119 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (119 CVEs).

Media Mentions

Signals from CVEs in this product scope (119 CVEs).

Top CNAs Publishing CVEs For Enterprise Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9.026.80.5%00
3.8.025.30.5%00
3.7.039.51.3%00
3.21.118.26.6%00
3.21.015.90.4%00
3.20.056.90.3%00
3.19.015.40.2%00
3.18.019.60.6%00
3.16.117.60.3%00
3.14.035.10.4%00
3.13.076.00.5%00
3.12.014.30.2%00
3.11.0105.50.5%00
3.10.016.50.6%00