检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FJJ5-V948-WHJJ CVE-2026-33646 | Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass) | 严重 | crates.iomise | 已审查 | 2026-06-23 01:19 | 2026-07-21 23:04 |
| GHSA-RHGP-6WQ6-9J67 CVE-2026-32315 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPImotioneye |
| 已审查 |
| 2026-06-23 01:11 |
| 2026-06-23 01:11 |
| GHSA-G9FX-5R4H-PCW3 CVE-2026-31978 | motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint | 中危 | PyPImotioneye | 已审查 | 2026-06-23 01:10 | 2026-06-23 01:10 |
| GHSA-W6J9-VW59-27WV CVE-2026-25119 | Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 01:09 | 2026-07-21 21:16 |
| GHSA-FFM6-VVPH-G5F5 CVE-2026-21887 | OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature | 高危 | PyPIpycti | 已审查 | 2026-06-23 01:01 | 2026-06-23 01:01 |
| GHSA-3QQ3-668M-V9MJ CVE-2025-64719 | Gogs has a Denial of Service in repository/wiki file listing web pages | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-23 00:58 | 2026-07-21 21:16 |
| GHSA-5PM9-R2M8-RCMJ CVE-2025-58048 | Paymenter vulnerable to Remote Code Execution via public file uploads | 严重 | Packagistpaymenter/paymenter | 已审查 | 2026-06-23 00:53 | 2026-06-23 00:53 |
| GHSA-4MVW-J8R9-XCGC CVE-2024-37155 | OpenCTI May Bypass Introspection Restriction | 中危 | PyPIpycti | 已审查 | 2026-06-23 00:43 | 2026-06-23 00:43 |
| GHSA-JCMP-JXH2-4JC3 | Duplicate Advisory: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:58 |
| GHSA-F95G-VM94-46C3 | Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:39 |
| GHSA-XJ2C-G5XP-4P47 | Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:06 |
| GHSA-PMM4-V8F6-4VPP | Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:41 |
| GHSA-F4H3-QHG5-J6MQ | Duplicate Advisory: Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:56 |
| GHSA-9R7J-7JHG-4F4C | Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:37 |
| GHSA-5W9J-W5P8-R4P7 | Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 04:47 |
| GHSA-869J-R97X-HX2G CVE-2026-59153 | Anki's local HTTP server does not sufficiently validate requests | 高危 | PyPIaqt | 已审查 | 2026-06-20 06:10 | 2026-07-16 05:58 |
| GHSA-JV2J-MQMW-XVV5 | SurrealDB: Denial of Service via deep operator chains | 中危 | crates.iosurrealdb | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-HV6H-HC26-Q48P | SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals | 中危 | crates.iosurrealdb | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-H4H3-3RFJ-X6FQ | SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field | 中危 | crates.iosurrealdb | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-CC8F-FCX3-GPJR | SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter | 高危 | crates.iosurrealdb | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-H5RG-8P7F-47G2 | SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch | 中危 | crates.iosurrealdb | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-4XGF-CPJX-PC3J | pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size | 中危 | PyPIpydantic-settings | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-G2GW-Q38M-VJFC | Lokka: Azure Resource Manager URL path validation issue | 高危 | npm@merill/lokka | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-H5X8-XP6M-X6Q4 | @jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing | 高危 | npm@jhb.software/payload-cloudinary-plugin | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-F4XH-W4CJ-QXQ8 | LangSmith SDK TracingMiddleware: Arbitrary server-side file read | 高危 | PyPIlangsmith | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |