检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3XCQ-8MJW-H6MX CVE-2026-22599 | Strapi Vulnerable to SQL Injection in Content Type Builder | 严重 | npm@strapi/content-type-builder+1 | 已审查 | 2026-05-14 04:02 | 2026-05-16 07:44 |
| GHSA-7MQX-WWH4-F9FW CVE-2025-64526 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying |
| 中危 |
npm@strapi/plugin-users-permissions |
| 已审查 |
| 2026-05-14 04:02 |
| 2026-05-16 07:44 |
| GHSA-27QC-M5GF-JV5R CVE-2026-45375 | SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-13 23:33 | 2026-06-09 04:13 |
| GHSA-GMMV-4CC5-WR9R CVE-2026-45371 | SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-13 23:33 | 2026-05-16 07:45 |
| GHSA-429Q-FHH4-R6HJ | Anchor: `InterfaceAccount` allows account substitution between unexpected types | 高危 | crates.ioanchor-lang | 已审查 | 2026-05-13 23:33 | 2026-05-20 04:18 |
| GHSA-V25J-WQCW-FVHJ | wger has an Uncontrolled Resource Consumption issue | 中危 | PyPIwger | 已审查 | 2026-05-13 23:33 | 2026-05-13 23:33 |
| GHSA-2RGP-F66F-4499 CVE-2026-45083 | Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy | 严重 | Mavenio.goobi.viewer:viewer-core | 已审查 | 2026-05-13 23:33 | 2026-06-09 07:55 |
| GHSA-QQQ4-5773-PMW5 CVE-2026-45152 | uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution | 高危 | Gogitlab.com/uniget-org/cli | 已审查 | 2026-05-13 23:33 | 2026-06-09 07:54 |
| GHSA-FMH9-GPQH-G53G CVE-2026-45148 | SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-13 23:33 | 2026-05-16 07:45 |
| GHSA-6R88-8V7Q-Q4P2 CVE-2026-45147 | SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-05-13 23:32 | 2026-05-16 07:45 |
| GHSA-VW82-7FV8-R6GP | Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server | 严重 | Gogithub.com/obot-platform/obot | 已审查 | 2026-05-13 23:32 | 2026-05-13 23:32 |
| GHSA-C6RC-8JPP-2FGC CVE-2026-45137 | Anchor: Program<'info, System> is not properly validated | 高危 | crates.ioanchor-lang | 已审查 | 2026-05-13 23:31 | 2026-06-09 07:54 |
| GHSA-G3XQ-3GMV-QQ8G CVE-2026-45136 | claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh | 高危 | npmclaude-code-cache-fix | 已审查 | 2026-05-13 23:31 | 2026-06-09 07:54 |
| GHSA-P3HX-PWF3-J8WR CVE-2026-44798 | Nautobot: GitRepository.current_head field should not be writable through REST API | 高危 | PyPInautobot | 已审查 | 2026-05-13 23:31 | 2026-06-09 18:18 |
| GHSA-C35Q-VXRP-PH26 CVE-2026-44797 | Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) | 高危 | PyPInautobot | 已审查 | 2026-05-13 23:30 | 2026-06-09 18:18 |
| GHSA-QRPW-GJVH-X5GM CVE-2026-44796 | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) | 中危 | PyPInautobot | 已审查 | 2026-05-13 23:30 | 2026-06-09 10:01 |
| GHSA-WPXJ-44W3-2J6X CVE-2026-44794 | Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference | 中危 | PyPInautobot | 已审查 | 2026-05-13 23:30 | 2026-06-09 10:01 |
| GHSA-96QJ-4JJ5-WCJC CVE-2026-44774 | Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false | 中危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-05-13 23:29 | 2026-05-16 07:50 |
| GHSA-M3XC-H892-GGX6 CVE-2026-44740 | go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | 中危 | Gogithub.com/go-git/go-billy/v5+1 | 已审查 | 2026-05-13 23:29 | 2026-06-09 18:50 |
| GHSA-J274-39QW-32C9 CVE-2026-44738 | Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-13 23:29 | 2026-05-13 23:29 |
| GHSA-3644-Q5CJ-C5C7 CVE-2026-45134 | LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning | 高危 | npmlangchain+2 | 已审查 | 2026-05-13 23:29 | 2026-06-09 07:54 |
| GHSA-HVX9-HWR7-WJJ9 CVE-2026-44724 | Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name | 高危 | npmsysteminformation | 已审查 | 2026-05-13 23:29 | 2026-06-09 07:53 |
| GHSA-223G-F5MQ-GW33 CVE-2026-44720 | OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover | 中危 | npmopenlearnx | 已审查 | 2026-05-13 09:39 | 2026-06-09 07:54 |
| GHSA-XR5H-PHRJ-8VXV CVE-2026-45028 | Astro: Server island encrypted parameters vulnerable to cross-component replay | 低危 | npmastro | 已审查 | 2026-05-13 09:36 | 2026-05-15 04:38 |
| GHSA-87M7-QFFR-542V CVE-2026-44697 | Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-05-13 09:36 | 2026-07-21 21:53 |