CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-48384 KEV HIGH

Git allows arbitrary code execution through broken config quoting

CVSS 8.1 EPSS 4.20% Jul 8, 2025
CVE-2025-48385 HIGH

Git alllows arbitrary file writes via bundle-uri parameter injection

CVSS 8.6 EPSS 1.02% Jul 8, 2025
CVE-2025-48386 MEDIUM

Git allows a buffer overflow in 'wincred' credential helper

CVSS 6.3 EPSS 0.41% Jul 8, 2025
CVE-2024-52005 HIGH

The sideband payload is passed unfiltered to the terminal in git

CVSS 7.5 EPSS 0.51% Jan 15, 2025
CVE-2024-50349 LOW

Git does not sanitize URLs when asking for credentials interactively

CVSS 2.1 EPSS 0.67% Jan 14, 2025
CVE-2024-52006 LOW

Newline confusion in credential helpers can lead to credential exfiltration in git

CVSS 2.1 EPSS 1.06% Jan 14, 2025
CVE-2024-21531 MEDIUM

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of th…

CVSS 5.3 EPSS 0.95% Oct 1, 2024
npm
CVE-2024-32465 HIGH

Git's protections for cloning untrusted repositories can be bypassed

CVSS 7.8 EPSS 1.03% May 14, 2024
CVE-2024-32021 HIGH

Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory

CVSS 7.1 EPSS 1.02% May 14, 2024
CVE-2024-32020 LOW

Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will

CVSS 3.9 EPSS 0.52% May 14, 2024
CVE-2024-32004 HIGH

Git vulnerable to Remote Code Execution while cloning special-crafted local repositories

CVSS 8.2 EPSS 1.35% May 14, 2024
CVE-2024-32002 CRITICAL

Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution

CVSS 9.1 EPSS 29.23% May 14, 2024
CVE-2023-29007 HIGH

Arbitrary configuration injection via `git submodule deinit`

CVSS 7.8 EPSS 6.08% Apr 25, 2023
CVE-2023-25652 HIGH

"git apply --reject" partially-controlled arbitrary file write

CVSS 7.5 EPSS 51.88% Apr 25, 2023
CVE-2023-23946 HIGH

Git's `git apply` overwriting paths outside the working tree

CVSS 7.5 EPSS 1.14% Feb 14, 2023
CVE-2023-22490 MEDIUM

Git vulnerable to local clone-based data exfiltration with non-local transports

CVSS 5.5 EPSS 0.71% Feb 14, 2023
CVE-2022-23521 CRITICAL

gitattributes parsing integer overflow in git

CVSS 9.8 EPSS 56.33% Jan 17, 2023
CVE-2022-41903 CRITICAL

Integer overflow in `git archive`, `git log --format` leading to RCE in git

CVSS 9.8 EPSS 44.27% Jan 17, 2023
CVE-2022-39260 HIGH

Git vulnerable to Remote Code Execution via Heap overflow in `git shell`

CVSS 8.8 EPSS 3.28% Oct 19, 2022
CVE-2022-39253 MEDIUM

Git subject to exposure of sensitive information via local clone of symbolic links

CVSS 5.5 EPSS 1.30% Oct 19, 2022
CVE-2022-29187 HIGH

Bypass of safe.directory protections in Git

CVSS 7.8 EPSS 0.45% Jul 12, 2022
CVE-2022-25648 CRITICAL

Command Injection

CVSS 9.8 EPSS 4.91% Apr 19, 2022
CVE-2021-23632 CRITICAL

Remote Code Execution (RCE)

CVSS 9.8 EPSS 2.35% Mar 17, 2022
npm
CVE-2021-21300 HIGH

malicious repositories can execute remote code while cloning

CVSS 8.0 EPSS 88.53% Mar 9, 2021
CVE-2020-11008 HIGH

Malicious URLs can still cause Git to send a stored credential to the wrong server

CVSS 7.5 EPSS 3.87% Apr 21, 2020

Showing 1 to 25 CVEs · page 1 (more available)