检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2XW4-V2WX-HQQ9 CVE-2026-44176 | Kirby CMS's `pages.access` permission is not checked during rendering of page drafts | 中危 | Packagistgetkirby/cms | 已审查 | 2026-05-27 07:55 | 2026-05-27 07:55 |
| GHSA-5FHX-9Q32-Q257 CVE-2026-44175 | Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistgetkirby/cms |
| 已审查 |
| 2026-05-27 07:49 |
| 2026-05-27 07:49 |
| GHSA-86RH-H242-J8XP CVE-2026-44174 | Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints | 高危 | Packagistgetkirby/cms | 已审查 | 2026-05-27 07:47 | 2026-05-27 07:47 |
| GHSA-RG3M-CFQ7-G6H6 CVE-2026-43947 | FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass | 高危 | npmfuxa-server | 已审查 | 2026-05-27 07:44 | 2026-05-27 07:44 |
| GHSA-FWCM-RQVW-J3P7 CVE-2026-43946 | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue | 高危 | npmfuxa-server | 已审查 | 2026-05-27 07:41 | 2026-05-27 07:41 |
| GHSA-P69W-MMFV-XRFJ CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | 高危 | npm@frangoteam/fuxa | 已审查 | 2026-05-27 07:40 | 2026-05-27 07:40 |
| GHSA-CQH3-JG8P-336J CVE-2026-42568 | Yamcs Vulnerable to LDAP Injection in LdapAuthModule | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-05-27 07:39 | 2026-06-11 22:05 |
| GHSA-9RFG-V8G9-9367 CVE-2026-42462 | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring | 高危 | npm@fedify/fedify | 已审查 | 2026-05-27 07:38 | 2026-06-11 21:30 |
| GHSA-VV9J-GJW2-J8WP CVE-2026-42089 | yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation | 高危 | npmyeoman-environment | 已审查 | 2026-05-27 07:10 | 2026-07-09 01:36 |
| GHSA-F659-372H-6X3X CVE-2026-41207 | netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures | 中危 | Mavenio.netty.incubator:netty-incubator-codec-ohttp | 已审查 | 2026-05-27 07:08 | 2026-06-09 19:53 |
| GHSA-RH28-MQJ4-8X59 CVE-2026-48048 | XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests | 高危 | Mavenorg.xwiki.platform:xwiki-platform-livetable-ui | 已审查 | 2026-05-27 04:16 | 2026-05-27 04:17 |
| GHSA-VGWR-23FQ-PR7G CVE-2026-48047 | XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin | 中危 | Mavenorg.xwiki.platform:xwiki-platform-webjars-api | 已审查 | 2026-05-27 03:33 | 2026-05-27 03:33 |
| GHSA-FGMM-W5CX-VRFW CVE-2026-35202 | Pterodactyl has a database resource limit bypass via race condition in Client API | 低危 | Packagistpterodactyl/panel | 已审查 | 2026-05-27 03:30 | 2026-06-09 19:00 |
| GHSA-G2G4-47GV-P72V CVE-2026-26028 | CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS | 中危 | npmcryptpad | 已审查 | 2026-05-27 03:05 | 2026-05-27 03:05 |
| GHSA-QRVH-R3F2-9H4R CVE-2026-33137 | XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName} | 严重 | Mavenorg.xwiki.platform:xwiki-platform-rest-server | 已审查 | 2026-05-27 02:58 | 2026-05-27 02:58 |
| GHSA-HQMV-V56G-4M47 CVE-2026-39964 | Typebot.io has stored XSS via `javascript`: URI in text bubble links — bot author executes JS on visitors' browsers | 中危 | npm@typebot.io/js | 已审查 | 2026-05-27 02:00 | 2026-05-27 02:00 |
| GHSA-6M7C-XFHP-P9FH CVE-2026-28445 | Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview | 高危 | npm@typebot.io/js | 已审查 | 2026-05-27 01:39 | 2026-05-27 01:39 |
| GHSA-XQ3R-2QV5-VQQM CVE-2026-23734 | XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash | 严重 | Mavenorg.xwiki.commons:xwiki-commons-classloader-api | 已审查 | 2026-05-27 01:16 | 2026-05-27 01:16 |
| GHSA-HFPV-MC5V-P9MM CVE-2025-66407 | Weblate has a Server-Side Request Forgery issue | 中危 | PyPIWeblate | 已审查 | 2026-05-27 00:41 | 2026-05-27 00:41 |
| GHSA-M4F9-C775-WG56 | Duplicate Advisory: gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules 已撤回 | 高危 | crates.iogix | 已审查 | 2026-05-26 23:32 | 2026-07-01 01:40 |
| GHSA-98F3-HWG4-4RF7 CVE-2026-9540 | vllm has Improper Resource Shutdown or Release | 中危 | PyPIvllm | 已审查 | 2026-05-26 23:32 | 2026-07-01 01:43 |
| GHSA-7JCP-V9W4-WJMG CVE-2026-7374 | KubeVirt has a Link Following vulnerability | 严重 | Gokubevirt.io/kubevirt | 已审查 | 2026-05-26 23:32 | 2026-07-01 02:04 |
| GHSA-W4PP-8PJF-RMXW CVE-2026-9496 | pacote is vulnerable to Denial of Service (DoS) via the addGitSha function | 高危 | npmpacote | 已审查 | 2026-05-26 21:30 | 2026-08-28 00:39 |
| GHSA-47P6-69VM-VW6V CVE-2026-9495 | @koa/router has an Access Control Bypass | 中危 | npm@koa/router | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:39 |
| GHSA-H2P9-CR4H-PX24 CVE-2026-9520 | Blitz has a Cross-site Scripting issue | 低危 | npmblitz | 已审查 | 2026-05-26 21:30 | 2026-07-01 01:39 |