检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7GH7-258J-4MPQ CVE-2026-46672 | @actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper | 中危 | npm@actual-app/cli | 已审查 | 2026-06-23 05:42 | 2026-06-23 05:42 |
| GHSA-W856-8P3R-P338 CVE-2026-46611 | Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIglances |
| 已审查 |
| 2026-06-23 05:31 |
| 2026-07-21 22:44 |
| GHSA-42JC-V69J-G38F CVE-2026-39904 | Gophish contains a denial of service vulnerability | 高危 | Gogithub.com/gophish/gophish | 已审查 | 2026-06-23 05:31 | 2026-08-07 03:16 |
| GHSA-87QC-FJ39-WCCR CVE-2026-46608 | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533) | 高危 | PyPIglances | 已审查 | 2026-06-23 05:27 | 2026-07-21 22:44 |
| GHSA-9837-48HR-Q32J CVE-2026-46607 | Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution | 高危 | PyPIglances | 已审查 | 2026-06-23 05:21 | 2026-07-21 22:43 |
| GHSA-V5R2-QH84-FJX5 CVE-2026-46606 | Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py | 高危 | PyPIglances | 已审查 | 2026-06-23 05:14 | 2026-07-21 22:43 |
| GHSA-43X2-G84Q-FMQX CVE-2026-46495 | OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI | 严重 | Mavenorg.openidentityplatform.opendj:opendj-server-legacy | 已审查 | 2026-06-23 05:10 | 2026-06-23 05:10 |
| GHSA-R3CW-C95M-WFH9 CVE-2026-46488 | motionEye: Authentication possible via password hash | 严重 | PyPImotioneye | 已审查 | 2026-06-23 04:59 | 2026-06-23 04:59 |
| GHSA-C8Q4-9H32-2WW8 CVE-2026-44795 | Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types | 高危 | Mavenio.spinnaker.orca:orca-core+1 | 已审查 | 2026-06-23 04:43 | 2026-08-06 06:37 |
| GHSA-FHRQ-3GMX-P879 CVE-2026-44793 | OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget` | 低危 | Mavenorg.openidentityplatform.openam:openam-federation-library | 已审查 | 2026-06-23 04:39 | 2026-06-23 04:39 |
| GHSA-7CFQ-5MHV-JRP9 CVE-2026-44778 | Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected) | 低危 | Gogithub.com/inspektor-gadget/inspektor-gadget | 已审查 | 2026-06-23 04:35 | 2026-06-23 04:35 |
| GHSA-X93Q-X9PC-W5HW CVE-2026-44585 | Paymenter has broken object level authorization via service reference manipulation on ticket creation | 中危 | Packagistpaymenter/paymenter | 已审查 | 2026-06-23 04:30 | 2026-06-23 04:30 |
| GHSA-RV89-WCH8-C574 CVE-2026-44584 | Paymenter doesn't reset email verification status after email change | 中危 | Packagistpaymenter/paymenter | 已审查 | 2026-06-23 04:29 | 2026-06-23 04:29 |
| GHSA-7WWH-XCC3-9FCG CVE-2026-44583 | Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module | 中危 | Packagistpaymenter/paymenter | 已审查 | 2026-06-23 04:28 | 2026-06-23 04:28 |
| GHSA-49P4-PX3H-RQ49 CVE-2026-44517 | Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive | 中危 | Gogithub.com/containers/buildah | 已审查 | 2026-06-23 04:15 | 2026-06-23 04:15 |
| GHSA-FQ9H-C788-FX73 CVE-2026-44203 | OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl) | 严重 | Mavenorg.openidentityplatform.openam:openam-oauth2 | 已审查 | 2026-06-23 04:11 | 2026-06-23 04:11 |
| GHSA-C556-Q2MH-477V CVE-2026-44202 | OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` | 中危 | Mavenorg.openidentityplatform.openam:openam-core | 已审查 | 2026-06-23 04:10 | 2026-06-23 04:10 |
| GHSA-W56X-9778-RPPX CVE-2026-44179 | xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro | 严重 | Mavencom.xwiki.pro:xwiki-pro-macros | 已审查 | 2026-06-23 04:09 | 2026-06-23 04:09 |
| GHSA-XJVP-4FHW-GC47 CVE-2026-41579 | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | 中危 | Gogithub.com/opencontainers/runc | 已审查 | 2026-06-23 04:01 | 2026-06-23 04:01 |
| GHSA-2VG8-Q4C2-5CW3 CVE-2026-41573 | OpenAM has LDAP Injection via `_queryId` Parameter | 高危 | Mavenorg.openidentityplatform.openam:openam-core-rest | 已审查 | 2026-06-23 03:59 | 2026-06-23 03:59 |
| GHSA-95JH-7R58-XMXW CVE-2026-33731 | AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data | 中危 | Packagistwwbn/avideo | 已审查 | 2026-06-23 03:58 | 2026-06-23 03:58 |
| GHSA-95PQ-HR8P-F5G7 CVE-2025-67303 | ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420) | 高危 | PyPIcomfyui-manager | 已审查 | 2026-06-23 03:58 | 2026-06-23 03:58 |
| GHSA-WF69-R4MX-43RR CVE-2026-33692 | AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration | 高危 | Packagistwwbn/avideo | 已审查 | 2026-06-23 03:54 | 2026-06-23 03:54 |
| GHSA-GH82-F9X8-5FRX CVE-2026-12479 | Keras: DiskIOStore permits path traversal through crafted layer names | 中危 | PyPIkeras | 已审查 | 2026-06-23 02:34 | 2026-08-08 04:13 |
| GHSA-8J8M-P79X-G4JM CVE-2026-33684 | AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions | 中危 | Packagistwwbn/avideo | 已审查 | 2026-06-23 01:25 | 2026-06-23 01:25 |