检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5X9F-6VG5-QG4M CVE-2026-45720 | Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token | 高危 | Gogithub.com/siderolabs/omni | 已审查 | 2026-06-05 23:25 | 2026-06-05 23:25 |
| GHSA-4C5C-2VC3-X5W2 CVE-2024-27928 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIvantage6 |
| 已审查 |
| 2026-06-05 23:24 |
| 2026-06-05 23:24 |
| GHSA-5549-C5Q7-FJ65 CVE-2024-24769 | Vantage6: No limit on emails sent for password/MFA reset | 低危 | PyPIvantage6 | 已审查 | 2026-06-05 23:21 | 2026-06-05 23:24 |
| GHSA-W8P5-MX5W-CPQJ CVE-2026-11332 | ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution | 高危 | PyPIansible-core | 已审查 | 2026-06-05 17:33 | 2026-07-17 03:30 |
| GHSA-H39J-R5QQ-R9MM CVE-2026-10732 | decompress: Arbitrary File Write via Archive Extraction (Zip Slip) | 中危 | npmdecompress | 已审查 | 2026-06-05 17:33 | 2026-07-29 23:51 |
| GHSA-6G26-7CX5-MRRG CVE-2026-9088 | Keycloak: Information disclosure due to user profile permission bypass | 低危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2026-06-05 17:33 | 2026-07-17 03:26 |
| GHSA-2VRG-7RQV-PRF9 CVE-2026-11312 | bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map | 低危 | PyPIinfinistore | 已审查 | 2026-06-05 11:31 | 2026-07-16 07:37 |
| GHSA-Q3G8-RJRX-59PH CVE-2026-50589 | OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash | 中危 | PyPIironic | 已审查 | 2026-06-05 08:31 | 2026-07-16 07:30 |
| GHSA-4P62-HQP5-G644 CVE-2026-47708 | MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper | 严重 | PyPIstata-mcp | 已审查 | 2026-06-05 05:00 | 2026-06-05 05:00 |
| GHSA-XGX4-4H9W-53PV CVE-2026-47703 | AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle | 中危 | Gogithub.com/AdguardTeam/AdGuardHome+1 | 已审查 | 2026-06-05 03:50 | 2026-07-21 03:05 |
| GHSA-JPVJ-WPMJ-H7RV | Supply chain compromise via malicious @cap-js/openapi | 严重 | npm@cap-js/openapi | 已审查 | 2026-06-05 03:37 | 2026-06-05 03:37 |
| GHSA-GQ96-5PFX-F4VC CVE-2026-48013 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:36 | 2026-06-05 03:36 |
| GHSA-XVHC-GM7J-MHMC CVE-2026-48015 | Shopware: Stored XSS via SVG file upload — no SVG sanitization | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:35 | 2026-06-05 03:35 |
| GHSA-9V5M-39WH-5CHQ CVE-2026-48016 | Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:33 | 2026-06-05 03:33 |
| GHSA-F8Q6-3G5W-JJR6 CVE-2026-48014 | Shopware: Admin API ACL Bypass in Order State Transition Endpoints | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:33 | 2026-06-05 03:33 |
| GHSA-4X3X-869W-XX3M CVE-2026-48012 | Shopware SSO referer trust leading to an arbitrary redirect target | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:32 | 2026-06-05 03:32 |
| GHSA-7W52-7JVM-M9VW CVE-2026-48011 | Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames | 低危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:31 | 2026-06-11 22:06 |
| GHSA-V39M-97P8-GQG7 CVE-2026-48010 | Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:28 | 2026-06-05 03:28 |
| GHSA-8V9P-G828-V98F CVE-2026-48009 | Shopware: Admin Account Takeover via User Recovery Hash Exposure | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:27 | 2026-06-05 03:27 |
| GHSA-GV8P-48FR-4FXG CVE-2026-48008 | Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass | 中危 | Packagistshopware/core+1 | 已审查 | 2026-06-05 03:23 | 2026-06-05 03:23 |
| GHSA-8WHC-2WMV-WW35 CVE-2026-54458 | WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin | 严重 | PackagistWWBN/AVideo | 已审查 | 2026-06-05 02:57 | 2026-06-22 22:36 |
| GHSA-66Q5-CJ5G-WRFX CVE-2026-50183 | WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section | 中危 | PackagistWWBN/AVideo | 已审查 | 2026-06-05 02:56 | 2026-06-05 02:56 |
| GHSA-HGJH-6WJ8-GCGF CVE-2026-50182 | WWBN AVideo: Unauthenticated Reflected XSS via $_GET['search'] in AVideo YouTubeAPI Gallery Pagination | 中危 | PackagistWWBN/AVideo | 已审查 | 2026-06-05 02:55 | 2026-06-05 02:55 |
| GHSA-2FHX-Q92V-5FHV CVE-2026-49279 | WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass) | 高危 | Packagistwwbn/avideo | 已审查 | 2026-06-05 02:55 | 2026-06-05 02:55 |
| GHSA-9392-PJ54-QQF8 CVE-2026-47696 | WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint | 高危 | PackagistWWBN/AVideo | 已审查 | 2026-06-05 02:47 | 2026-06-05 02:47 |