检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WG2F-X2C2-C4RP CVE-2026-55461 | Snipe-IT has an Open Redirect After User Edit | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:57 | 2026-08-29 01:57 |
| GHSA-VGX7-C78R-69W9 CVE-2026-55460 | Snipe-IT has an authorization bypass on bulk editing users |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistsnipe/snipe-it |
| 已审查 |
| 2026-08-29 01:48 |
| 2026-08-29 01:48 |
| GHSA-WHRX-MMGR-GPCF CVE-2026-55452 | Snipe-IT has CSV formula injection in Activity Report export | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:46 | 2026-08-29 01:46 |
| GHSA-9272-WG2R-7XMX CVE-2026-55566 | Yamcs has DOM XSS in Extension Routing | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:32 | 2026-08-29 01:32 |
| GHSA-C64Q-HJ4J-375F CVE-2026-55565 | Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) | 严重 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:30 | 2026-08-29 01:30 |
| GHSA-73MF-M39P-WPM9 CVE-2026-55559 | Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) | 严重 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:23 | 2026-08-29 01:23 |
| GHSA-9JG3-G3WH-W9PJ CVE-2026-55552 | Yamcs has Unauthenticated Directory Traversal | 高危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:20 | 2026-08-29 01:20 |
| GHSA-RXPG-WJF8-QV9C CVE-2026-55549 | Yamcs has Reflected XSS in the URL of the Authorize Endpoint | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:17 | 2026-08-29 01:17 |
| GHSA-8XJQ-PR36-CCGF CVE-2026-55548 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:15 | 2026-08-29 01:15 |
| GHSA-CVW4-55PP-3HFQ CVE-2026-55547 | Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:13 | 2026-08-29 01:13 |
| GHSA-FWWW-CP23-7F5G CVE-2026-55545 | Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:10 | 2026-08-29 01:10 |
| GHSA-962X-CCWF-8X6P CVE-2026-55521 | Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities | 高危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:09 | 2026-08-29 01:09 |
| GHSA-3G44-3M7X-CGG2 CVE-2026-55511 | Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` | 严重 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:06 | 2026-08-29 01:06 |
| GHSA-X8MJ-6P3Q-G5PP CVE-2026-55068 | free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints | 严重 | Gogithub.com/free5gc/free5gc | 已审查 | 2026-08-29 00:58 | 2026-08-29 00:58 |
| GHSA-569V-Q83C-3J3G CVE-2026-55067 | Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment | 中危 | Gocode.vikunja.io/api | 已审查 | 2026-08-29 00:55 | 2026-08-29 00:55 |
| GHSA-5PG6-M483-7VRG CVE-2026-55066 | Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id | 高危 | Gocode.vikunja.io/api | 已审查 | 2026-08-29 00:52 | 2026-08-29 00:52 |
| GHSA-GG93-X632-9CCV CVE-2026-55065 | Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key | 高危 | Gocode.vikunja.io/api | 已审查 | 2026-08-29 00:50 | 2026-08-29 00:50 |
| GHSA-44V6-7FXQ-VGF4 CVE-2026-55064 | Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 | 中危 | Gocode.vikunja.io/api | 已审查 | 2026-08-29 00:39 | 2026-08-29 00:39 |
| GHSA-F27P-PW2P-9PR4 CVE-2026-54766 | Vikunja has a project duplication bypasses write-permission check on the target parent project | 中危 | Gocode.vikunja.io/api | 已审查 | 2026-08-29 00:37 | 2026-08-29 00:37 |
| GHSA-GPWF-4H98-V82Q CVE-2026-54788 | datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS | 高危 | crates.iodatadog-opentelemetry | 已审查 | 2026-08-29 00:35 | 2026-08-29 00:35 |
| GHSA-2WVM-8MVP-22QV CVE-2026-55834 | Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none | 中危 | Gogithub.com/pocket-id/pocket-id/backend | 已审查 | 2026-08-29 00:28 | 2026-08-29 00:28 |
| GHSA-MF5C-HW34-4HPP CVE-2026-55569 | Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory | 中危 | Gogithub.com/aquaproj/aqua/v2 | 已审查 | 2026-08-29 00:27 | 2026-08-29 00:27 |
| GHSA-CGC5-V3F2-8M2V CVE-2026-54755 | Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) | 严重 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-08-29 00:25 | 2026-08-29 00:25 |
| GHSA-P7GW-2PCP-5PF8 CVE-2026-54754 | Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) | 严重 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-08-29 00:22 | 2026-08-29 00:22 |
| GHSA-JW39-3688-R4RX CVE-2026-54757 | Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data | 高危 | PyPIcompliance-trestle | 已审查 | 2026-08-29 00:15 | 2026-08-29 00:15 |