检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-987X-96FQ-9384 | Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability 已撤回 | 中危 | NuGetMicrosoft.NetCore.App.Runtime.linux-arm | 已审查 | 2025-10-15 02:30 | 2025-10-16 01:38 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-GJ5F-73VH-WPF7 CVE-2025-11569 |
Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations 已撤回 |
| 低危 |
npmcross-zip |
| 已审查 |
| 2025-10-10 14:30 |
| 2025-10-21 01:49 |
| GHSA-WQ95-WR7M-26H4 | Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot 已撤回 | 高危 | npmflowise | 已审查 | 2025-10-06 11:31 | 2025-10-09 03:34 |
| GHSA-7RGR-72HP-9WP3 | Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel 已撤回 | 高危 | npmflowise | 已审查 | 2025-10-06 11:31 | 2025-10-09 03:34 |
| GHSA-26F6-WM47-7H7J | Duplicate Advisory: motionEye vulnerable to RCE via unsanitized motion config parameter 已撤回 | 高危 | PyPImotioneye | 已审查 | 2025-10-04 02:31 | 2025-11-04 05:48 |
| GHSA-98F8-J56X-2HH4 | Duplicate Advisory: SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions 已撤回 | 中危 | crates.iosurrealdb | 已审查 | 2025-09-26 23:30 | 2025-09-27 00:57 |
| GHSA-7X26-54JJ-CVHR | Duplicate Advisory: Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read) 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 14:30 | 2026-07-02 01:42 |
| GHSA-62MQ-GRC2-53J3 | Duplicate Advisory: Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-02 01:41 |
| GHSA-HVP2-4H2F-26W4 | Duplicate Advisory: Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-02 01:40 |
| GHSA-9P6C-JCW8-X98F | Duplicate Advisory: Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-01 05:26 |
| GHSA-95GX-JMHP-5P29 | Duplicate Advisory: Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-02 01:38 |
| GHSA-5GFQ-XRQ4-34RJ | Duplicate Advisory: Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-01 05:25 |
| GHSA-5FGF-Q57F-WWQF | Duplicate Advisory: Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule 已撤回 | 低危 | PyPIopenbabel | 已审查 | 2025-09-26 11:31 | 2026-07-01 02:48 |
| GHSA-8MJQ-32X3-22QF | Duplicate Advisory: Malicious versions of Nx were published 已撤回 | 严重 | npmnx | 已审查 | 2025-09-25 08:30 | 2025-09-26 00:34 |
| GHSA-M929-RG27-GJ99 | Duplicate Advisory: rollbar vulnerable to prototype pollution 已撤回 | 低危 | npmrollbar | 已审查 | 2025-09-25 05:30 | 2025-10-20 23:32 |
| GHSA-FFRW-9MX8-89P8 CVE-2025-57319 | Withdrawn Advisory: fast-redact vulnerable to prototype pollution 已撤回 | 低危 | npmfast-redact | 已审查 | 2025-09-25 05:30 | 2025-11-21 01:27 |
| GHSA-77WQ-646F-JRM2 | Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded. 已撤回 | 高危 | PyPIkeras | 已审查 | 2025-09-19 17:31 | 2025-09-20 01:34 |
| GHSA-HF6H-9WQ7-HMJG | Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2025-09-17 20:30 | 2025-09-18 04:24 |
| GHSA-J424-MC44-F4HJ | Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2025-09-17 20:30 | 2025-09-18 04:24 |
| GHSA-4VR7-G93G-CF6M | Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2025-09-17 20:30 | 2025-09-18 04:24 |
| GHSA-QHWP-454G-2GV4 | Duplicate Advisory: express-xss-sanitizer has an unbounded recursion depth 已撤回 | 中危 | npmexpress-xss-sanitizer | 已审查 | 2025-09-15 08:30 | 2025-09-26 22:38 |
| GHSA-XMCW-MV9P-7PQ2 | Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks 已撤回 | 中危 | Mavenorg.keycloak:keycloak-account-ui+1 | 已审查 | 2025-09-06 05:32 | 2025-12-20 13:46 |
| GHSA-CXM3-WV7P-598C CVE-2025-10894 | Malicious versions of Nx were published 已撤回 | 严重 | npm@nx/devkit+7 | 已审查 | 2025-08-28 00:42 | 2026-07-28 20:42 |
| GHSA-W2WJ-HW98-233H | Duplicate Advisory: Keycloak Potential Variable Reference in Model Storage Services 已撤回 | 中危 | Mavenorg.keycloak:keycloak-model-storage-services | 已审查 | 2025-08-22 02:31 | 2025-10-09 07:32 |
| GHSA-XH9H-692F-MMG4 CVE-2025-54364 | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module 已撤回 | 低危 | PyPIknack | 已审查 | 2025-08-20 11:30 | 2025-08-30 04:14 |