检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5389-F7VH-WXJ8 CVE-2026-47728 | Bugsink: Project scoping missing in sourcemap and debug-file lookup | 中危 | PyPIbugsink | 已审查 | 2026-06-06 05:44 | 2026-06-06 05:44 |
| GHSA-G5VC-Q7QC-V939 CVE-2026-47716 | Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
PyPIbugsink |
| 已审查 |
| 2026-06-06 05:43 |
| 2026-06-06 05:43 |
| GHSA-VX2F-6M6H-9FRF CVE-2026-47715 | Bugsink: Issue event views can show an event from another project if its UUID is known | 低危 | PyPIbugsink | 已审查 | 2026-06-06 05:43 | 2026-06-06 05:43 |
| GHSA-2Q52-X2FF-QGFR CVE-2026-24425 | Twig: Possible sandbox bypass when using a source policy | 高危 | Packagisttwig/twig | 已审查 | 2026-06-06 04:41 | 2026-06-06 04:41 |
| GHSA-C3QP-2GGW-XJG7 CVE-2026-47744 | Shopper: Authorization bypass and RBAC privilege escalation in team settings | 严重 | Packagistshopper/framework | 已审查 | 2026-06-06 04:35 | 2026-06-06 04:35 |
| GHSA-HR9V-R8R2-HG7J CVE-2026-47743 | Shopper: Multiple data integrity and disclosure issues in admin Livewire components | 高危 | Packagistshopper/framework | 已审查 | 2026-06-06 04:35 | 2026-06-06 04:35 |
| GHSA-FXQW-97CC-7G5C CVE-2026-47745 | Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables | 中危 | Packagistshopper/framework | 已审查 | 2026-06-06 04:34 | 2026-06-06 04:34 |
| GHSA-H4MP-G9C6-XWPH CVE-2026-47742 | Shopper: Missing authorization on Product admin Livewire sub-form components | 中危 | Packagistshopper/framework | 已审查 | 2026-06-06 04:33 | 2026-06-06 04:33 |
| GHSA-VG35-5WQ7-3X7W CVE-2026-47761 | TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection | 高危 | npmtinymce+2 | 已审查 | 2026-06-06 04:29 | 2026-07-01 05:11 |
| GHSA-V98H-VMPC-FPQV CVE-2026-47762 | TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments | 高危 | npmtinymce+2 | 已审查 | 2026-06-06 04:29 | 2026-07-16 05:07 |
| GHSA-Q742-QVGC-GC2F CVE-2026-47759 | TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes | 高危 | npmtinymce+2 | 已审查 | 2026-06-06 04:27 | 2026-07-08 01:10 |
| GHSA-MH5M-5HW4-5C69 CVE-2026-47760 | TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs | 高危 | npmtinymce+2 | 已审查 | 2026-06-06 04:09 | 2026-06-06 04:09 |
| GHSA-WX3M-WHQV-XV47 | skillctl: Path traversal and symlink-follow in skillctl allow arbitrary file disclosure and deletion | 高危 | crates.ioskillctl | 已审查 | 2026-06-06 03:43 | 2026-06-06 03:46 |
| GHSA-P462-PRXW-MJX4 CVE-2026-47731 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) | 严重 | PyPIait-core | 已审查 | 2026-06-06 02:11 | 2026-06-06 02:11 |
| GHSA-X9F6-9RVM-MMRG CVE-2026-54533 | vantage6 node has an Improper Access Control issue | 中危 | PyPIvantage6 | 已审查 | 2026-06-06 00:45 | 2026-07-10 05:06 |
| GHSA-FGMC-2HQJ-86V4 CVE-2026-54445 | Vantage6: Set admin user and password from environment or configuration | 中危 | PyPIvantage6 | 已审查 | 2026-06-06 00:45 | 2026-07-10 05:06 |
| GHSA-G72G-R7M4-9X4G CVE-2026-53926 | NocoDB: OAuth Tokens Persist Through Security Events | 中危 | npmnocodb | 已审查 | 2026-06-06 00:43 | 2026-07-21 05:19 |
| GHSA-RM5C-5X2P-48WR CVE-2026-52878 | Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-06-06 00:42 | 2026-06-10 02:40 |
| GHSA-W4C6-7R69-W7J9 CVE-2026-52880 | klever-go: REST API slow-header connection exhaustion via Gin Engine.Run | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-06-06 00:41 | 2026-06-10 02:40 |
| GHSA-HF2G-6J7H-98WG CVE-2026-52879 | klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-06-06 00:41 | 2026-06-10 02:40 |
| GHSA-FW38-PC54-JVX9 CVE-2026-49343 | Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS | 中危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-06-06 00:40 | 2026-06-06 00:40 |
| GHSA-HV83-GGC4-V385 CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | 高危 | npmdbgate-api | 已审查 | 2026-06-06 00:39 | 2026-07-09 01:36 |
| GHSA-Q4X5-8CJ6-52WG CVE-2026-47684 | Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP | 高危 | npm@sync-in/server | 已审查 | 2026-06-06 00:34 | 2026-07-09 01:36 |
| GHSA-JJRM-HR5F-673X CVE-2026-47680 | Source controller: Improper path handling allows traversal | 中危 | Gogithub.com/fluxcd/source-controller | 已审查 | 2026-06-06 00:32 | 2026-06-06 00:32 |
| GHSA-WM5R-5QP3-5VXF CVE-2026-47670 | Authenticated Remote Code Execution via loadReader functionName code injection in DbGate | 严重 | npmdbgate-api | 已审查 | 2026-06-06 00:30 | 2026-06-06 00:30 |