检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JH32-V29G-68PQ CVE-2026-49741 | TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework | 高危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 03:32 | 2026-06-13 03:32 |
| GHSA-QCMW-6RM2-5X78 CVE-2026-47350 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagisttypo3/cms-core |
| 已审查 |
| 2026-06-13 03:32 |
| 2026-06-13 03:32 |
| GHSA-HWVQ-2W67-RVXP CVE-2026-47346 | TYPO3 CMS has Broken Access Control in its Form Framework | 高危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 03:32 | 2026-06-13 03:32 |
| GHSA-CHM7-4VCH-H8VR CVE-2026-49742 | TYPO3 CMS has Broken Access Control in its Media Module | 高危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 03:09 | 2026-06-13 03:09 |
| GHSA-C78M-C52X-JGWP CVE-2026-49740 | TYPO3 CMS has Insecure Deserialization via Core API | 中危 | Packagisttypo3/cms-core | 已审查 | 2026-06-13 03:09 | 2026-06-13 03:09 |
| GHSA-JF56-V8JC-JCC5 CVE-2026-49738 | TYPO3 CMS has Broken Access Control in its File Abstraction Layer | 低危 | Packagisttypo3/cms-core | 已审查 | 2026-06-13 03:09 | 2026-06-13 03:09 |
| GHSA-2J54-93Q2-3HJQ CVE-2026-47352 | TYPO3 CMS has Broken Access Control in Backend API | 中危 | Packagisttypo3/cms-backend+1 | 已审查 | 2026-06-13 03:08 | 2026-06-13 03:08 |
| GHSA-Q93M-25XV-94HH CVE-2026-47351 | TYPO3 CMS: Broken Access Control in Media Module | 中危 | Packagisttypo3/cms-backend+1 | 已审查 | 2026-06-13 03:06 | 2026-06-13 03:06 |
| GHSA-CG75-QFG2-W9HJ CVE-2026-47348 | TYPO3 CMS has Cross-Site Scripting in Indexed Search | 中危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 03:06 | 2026-06-13 03:06 |
| GHSA-JVF5-RXVV-3MCG CVE-2026-47344 | TYPO3 HTML Sanitizer allows Cross-site Scripting | 低危 | Packagisttypo3/html-sanitizer | 已审查 | 2026-06-13 03:06 | 2026-06-13 03:06 |
| GHSA-RP4V-QC77-PHM4 CVE-2026-3433 | Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:30 |
| GHSA-M2W9-H2MM-79QR CVE-2026-6739 | Mattermost doesn't require system-level permission when patching protected default system roles | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:43 |
| GHSA-C28Q-M4GF-VG4Q CVE-2026-6689 | Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:35 |
| GHSA-9P44-R552-4WP9 CVE-2026-7184 | Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:48 |
| GHSA-8QQ9-CQJ8-82W4 CVE-2026-6961 | Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync | 高危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:45 |
| GHSA-6HXM-W4HV-VGVW CVE-2026-7387 | Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints | 高危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:51 |
| GHSA-3VMP-WHVV-5V9V CVE-2026-6046 | Mattermost doesn't validate that a username returned during bot registration belongs to a bot account | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-06-13 02:31 | 2026-08-25 05:39 |
| GHSA-XPH7-9RJV-W5FR CVE-2026-45831 | ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to | 高危 | PyPIchromadb | 已审查 | 2026-06-13 02:31 | 2026-08-25 04:00 |
| GHSA-36P7-VC44-83PF CVE-2026-45833 | ChromaDB has a code injection vulnerability | 严重 | PyPIchromadb | 已审查 | 2026-06-13 02:31 | 2026-08-25 04:03 |
| GHSA-2WM9-HF6C-P5CR CVE-2026-45830 | ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection | 高危 | PyPIchromadb | 已审查 | 2026-06-13 02:31 | 2026-08-25 03:57 |
| GHSA-CX3H-4QPV-8HC9 CVE-2026-49854 | Tornado has out-of-bounds memory access via C extension | 低危 | PyPItornado | 已审查 | 2026-06-13 02:30 | 2026-06-13 02:30 |
| GHSA-6VGG-XHVH-38FF | nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store | 低危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-13 02:30 | 2026-06-13 02:30 |
| GHSA-248M-82V9-Q6G6 CVE-2026-48156 | pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams | 中危 | PyPIpypdf | 已审查 | 2026-06-13 02:29 | 2026-06-13 02:29 |
| GHSA-CJ93-CHG6-VGV8 CVE-2026-48155 | pypdf: Possible large memory usage for large offsets for layout mode text | 中危 | PyPIpypdf | 已审查 | 2026-06-13 02:29 | 2026-06-13 02:29 |
| GHSA-CPWG-X64R-RGWG CVE-2026-48154 | gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362) | 中危 | Gogithub.com/pilinux/gorest | 已审查 | 2026-06-13 02:29 | 2026-06-13 02:29 |