检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7CQP-7CFV-6C3Q | AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel | 中危 | Packagistwwbn/avideo | 已审查 | 2026-06-24 03:11 | 2026-06-24 04:41 |
| GHSA-PHV5-334H-MXCW | motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
PyPImotioneye |
| 已审查 |
| 2026-06-24 03:09 |
| 2026-06-24 03:09 |
| GHSA-QXVG-H7Q2-HCXH | motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE) | 严重 | PyPImotioneye | 已审查 | 2026-06-24 02:53 | 2026-06-24 02:53 |
| GHSA-J67X-Q29F-QCVV CVE-2026-55863 | motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution | 中危 | PyPImotioneye | 已审查 | 2026-06-24 02:37 | 2026-06-24 02:37 |
| GHSA-RW9Q-97R9-8GVH CVE-2026-55488 | motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read | 高危 | PyPImotioneye | 已审查 | 2026-06-24 02:32 | 2026-06-24 02:32 |
| GHSA-29HF-RM4X-XXPH CVE-2026-55448 | Mise's local credential_command executes untrusted config | 中危 | crates.iomise | 已审查 | 2026-06-24 02:24 | 2026-06-24 02:24 |
| GHSA-77G9-363W-RCCQ CVE-2026-55441 | Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository | 高危 | crates.iomise | 已审查 | 2026-06-24 02:24 | 2026-06-24 02:24 |
| GHSA-F94H-J2QG-FXW3 CVE-2026-54557 | mise HTTP backend uses raw version path for install symlink destination | 中危 | crates.iomise | 已审查 | 2026-06-24 02:13 | 2026-07-21 23:04 |
| GHSA-J4H9-PM27-4RFW CVE-2026-54134 | OctoPrint has possible file exfiltration via query parameters on upload endpoints | 高危 | PyPIOctoPrint | 已审查 | 2026-06-24 02:03 | 2026-08-22 02:28 |
| GHSA-3VWC-QWHC-3MJ7 CVE-2026-53925 | Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration | 高危 | PyPIglances | 已审查 | 2026-06-24 01:59 | 2026-07-21 22:44 |
| GHSA-8QV3-P479-CJ62 CVE-2026-54350 | Budibase has nonymous NoSQL operator injection via published-app query templates | 严重 | npm@budibase/server | 已审查 | 2026-06-24 01:43 | 2026-08-13 02:57 |
| GHSA-WC3F-XC32-435F CVE-2026-55173 | AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink | 高危 | Packagistwwbn/avideo | 已审查 | 2026-06-24 01:42 | 2026-06-24 01:42 |
| GHSA-3W28-36P9-W929 CVE-2026-52816 | Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:33 | 2026-07-21 21:17 |
| GHSA-R9PV-5RPP-VM8G CVE-2026-45049 | OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet | 高危 | Mavenorg.openidentityplatform.openam:openam-federation | 已审查 | 2026-06-24 01:33 | 2026-06-24 01:33 |
| GHSA-VVHJ-W2JQ-263Q CVE-2026-45048 | OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC | 高危 | Mavenorg.openidentityplatform.openam:openam-core | 已审查 | 2026-06-24 01:33 | 2026-06-24 01:33 |
| GHSA-P6QX-GHXM-389H CVE-2026-35163 | OctoPrint has XSS in its Suppressed Command Notifications | 中危 | PyPIOctoPrint | 已审查 | 2026-06-24 01:15 | 2026-08-22 02:26 |
| GHSA-744X-3838-5R56 CVE-2026-52815 | Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:13 | 2026-07-21 21:40 |
| GHSA-XP79-5MX3-JX52 CVE-2026-52814 | Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:12 | 2026-07-21 21:40 |
| GHSA-C39W-43GM-34H5 CVE-2026-52813 | Gogs has Path Traversal in organization name that results in RCE through Git hooks | 严重 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:10 | 2026-07-21 21:40 |
| GHSA-6P9M-Q3JP-47H4 CVE-2026-52812 | Gogs: LFS dedupe path leaks private repo content across tenants | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:10 | 2026-07-21 21:40 |
| GHSA-89MR-XQFV-758M CVE-2026-52811 | Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym | 严重 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:09 | 2026-07-21 21:40 |
| GHSA-WMFG-5P4H-5FW3 CVE-2026-52810 | Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:03 | 2026-07-21 21:40 |
| GHSA-5C3F-6486-3G7G CVE-2026-52809 | Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:03 | 2026-07-21 21:17 |
| GHSA-268J-37XF-PP52 CVE-2026-52808 | Gogs's write-level collaborators can mutate admin-only repository settings via API | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:03 | 2026-07-21 21:39 |
| GHSA-VCM5-GVMP-78MP CVE-2026-52807 | Gogs has DOM-based XSS via Milestone Name on New Issue Page | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:02 | 2026-07-21 21:35 |