检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RPGQ-M5FP-32WR CVE-2026-44881 | Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | 高危 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:23 | 2026-06-09 18:25 |
| GHSA-7FW3-X4R2-G7WC CVE-2026-44850 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/portainer/portainer |
| 已审查 |
| 2026-05-15 00:23 |
| 2026-06-09 18:25 |
| GHSA-M8FG-67J7-CX4V CVE-2026-44885 | Portainer has a path traversal in backup archive extraction that allows arbitrary file write | 中危 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:23 | 2026-06-09 18:25 |
| GHSA-RRMM-9V76-H3P4 CVE-2026-44848 | Portainer missing authorization on Docker plugin endpoints, which allows host RCE | 严重 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:22 | 2026-06-09 18:24 |
| GHSA-WXRR-JP8M-QQ7F CVE-2026-46480 | FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-06-10 02:40 |
| GHSA-MQ53-PC65-WJC4 CVE-2026-46479 | FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-07-07 21:34 |
| GHSA-7J65-65CR-6644 CVE-2026-46478 | FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-07-07 21:34 |
| GHSA-5H9V-837X-M97R CVE-2026-46477 | FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-07-07 21:34 |
| GHSA-728H-4MWJ-F2P4 CVE-2026-46476 | FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-06-09 21:10 |
| GHSA-78PR-C5X5-JGGC CVE-2026-46475 | FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-06-13 03:31 |
| GHSA-HMG2-JJJX-JCP2 CVE-2026-46444 | FlowiseAI: Vector Store No Permission Checks | 高危 | npmflowise | 已审查 | 2026-05-15 00:19 | 2026-06-11 22:08 |
| GHSA-6QF2-7X63-MM6V CVE-2026-45076 | Synapse pagination Denial of Service | 中危 | PyPImatrix-synapse | 已审查 | 2026-05-15 00:18 | 2026-06-09 18:18 |
| GHSA-8Q93-326V-3M7G CVE-2026-45078 | Synapse CPU starvation (Denial of Service) | 高危 | PyPImatrix-synapse | 已审查 | 2026-05-15 00:18 | 2026-06-09 18:18 |
| GHSA-6H4J-WCR9-2VG7 CVE-2026-45732 | n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints | 高危 | npmn8n | 已审查 | 2026-05-15 00:18 | 2026-07-20 21:41 |
| GHSA-MHRX-QHRJ-673W CVE-2026-44792 | n8n Has a Source Control Pull SQL Injection | 高危 | npmn8n | 已审查 | 2026-05-15 00:18 | 2026-07-20 21:41 |
| GHSA-WRWR-H859-XH2R CVE-2026-44791 | n8n Has an XML Node Prototype Pollution Patch Bypass | 严重 | npmn8n | 已审查 | 2026-05-15 00:17 | 2026-07-20 21:40 |
| GHSA-57G9-58C2-XJG3 CVE-2026-44790 | n8n Has an Arbitrary File Read via Git Node | 严重 | npmn8n | 已审查 | 2026-05-15 00:17 | 2026-07-20 21:40 |
| GHSA-C8XV-5998-G76H CVE-2026-44789 | n8n: HTTP Request Node Pagination Prototype Pollution to RCE | 严重 | npmn8n | 已审查 | 2026-05-15 00:17 | 2026-07-20 21:40 |
| GHSA-CRQM-M339-7M2P CVE-2026-44722 | pyzipper has an encryption bypass for small files encrypted using it | 中危 | PyPIpyzipper | 已审查 | 2026-05-15 00:17 | 2026-05-15 00:17 |
| GHSA-9QPR-VC49-HQG2 CVE-2026-43978 | wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager | 高危 | PyPIwger | 已审查 | 2026-05-15 00:16 | 2026-05-15 00:16 |
| GHSA-CJ9G-27PH-4CGV CVE-2026-43977 | wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API | 高危 | PyPIwger | 已审查 | 2026-05-15 00:16 | 2026-05-15 00:16 |
| GHSA-HCWQ-X9FW-8CFQ CVE-2026-42853 | @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input | 中危 | npm@apostrophecms/cli | 已审查 | 2026-05-15 00:16 | 2026-06-13 06:01 |
| GHSA-Q23M-VM9R-5745 CVE-2026-43644 | podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints | 中危 | Gogithub.com/stefanprodan/podinfo | 已审查 | 2026-05-14 23:31 | 2026-05-20 23:48 |
| GHSA-7G73-99R4-M4MJ CVE-2026-46443 | FlowiseAI Vulnerable to Credential Data Leak | 高危 | npmflowise | 已审查 | 2026-05-14 22:58 | 2026-06-09 21:10 |
| GHSA-9RVC-VF7M-PGM2 CVE-2026-46442 | FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape | 严重 | npmflowise | 已审查 | 2026-05-14 22:57 | 2026-06-09 21:10 |