检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-65H7-C7C4-MGHX CVE-2026-2393 | MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability | 高危 | PyPImlflow | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:28 |
| GHSA-64VR-4GR2-M642 CVE-2026-30635 | automagik-genie has a command injection vulnerability |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmautomagik-genie |
| 已审查 |
| 2026-05-12 02:31 |
| 2026-05-18 23:27 |
| GHSA-RMXX-V9RJ-VPVG CVE-2026-6815 | Casdoor: Arbitrary file write possible through Local File System storage provider | 中危 | Gogithub.com/casdoor/casdoor | 已审查 | 2026-05-12 02:31 | 2026-07-09 05:00 |
| GHSA-P58C-Q354-6C4F CVE-2026-7817 | pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities | 高危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:51 |
| GHSA-J74F-G7VX-FH4X CVE-2026-7816 | pgAdmin 4: OS command injection vulnerability in Import/Export query export | 高危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:31 |
| GHSA-HV9P-2PQF-R5W3 CVE-2026-7820 | pgAdmin 4: Improper restriction of excessive authentication attempts | 中危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:02 |
| GHSA-HR4R-FWPV-C95J CVE-2026-7819 | pgAdmin 4 File Manager has symbolic-link path traversal | 高危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:56 |
| GHSA-HP84-P2GQ-6FVR CVE-2026-7815 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool | 高危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:23 |
| GHSA-H2X2-Q2MC-24GW CVE-2026-7813 | pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules | 严重 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:23 |
| GHSA-9F4Q-Q82Q-4359 CVE-2026-31248 | Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks | 高危 | PyPIdocling | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:21 |
| GHSA-7G5W-PQ96-8C5W CVE-2026-31253 | flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism | 高危 | PyPIflash_attn | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:22 |
| GHSA-6P2C-69CV-3FXQ CVE-2026-7814 | pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules | 中危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:32 |
| GHSA-4RHG-H8F2-V4JM CVE-2026-7818 | pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager | 高危 | PyPIpgadmin4 | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:12 |
| GHSA-M85W-WHWH-QVFX CVE-2026-31246 | GPT-Pilot contains a command injection vulnerability in the Executor.run() method | 中危 | PyPIgpt-pilot | 已审查 | 2026-05-12 02:31 | 2026-05-28 06:48 |
| GHSA-CR42-RG2M-MQ4Q CVE-2026-31247 | Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks | 高危 | PyPIdocling | 已审查 | 2026-05-12 02:31 | 2026-05-18 22:20 |
| GHSA-68W5-W573-Q2R8 CVE-2026-33052 | MantisBT Has Authorization Bypass in Global Profile Creation | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 01:58 | 2026-05-20 00:09 |
| GHSA-QQCJ-RGHW-829X CVE-2026-27478 | Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation | 严重 | Mavenio.unitycatalog:unitycatalog-server | 已审查 | 2026-05-12 01:58 | 2026-05-12 01:58 |
| GHSA-5C46-X3QW-Q7J7 CVE-2026-25244 | WebdriverIO BrowserStack Service has a Command Injection issue | 严重 | npm@wdio/browserstack-service | 已审查 | 2026-05-12 01:53 | 2026-05-20 00:08 |
| GHSA-H29G-C9CX-C73Q | torrentpier has PHP Serialize Injections | 严重 | Packagisttorrentpier/torrentpier | 已审查 | 2026-05-12 01:53 | 2026-05-12 01:53 |
| GHSA-26HH-7CQF-HHC6 CVE-2026-45109 | Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up | 高危 | npmnext | 已审查 | 2026-05-12 00:21 | 2026-05-15 04:39 |
| GHSA-PW8R-6689-XVF4 CVE-2026-44643 | Angular Expressions - Remote Code Execution using filters | 严重 | npmangular-expressions | 已审查 | 2026-05-12 00:20 | 2026-05-13 21:53 |
| GHSA-XH5J-727M-W6GG CVE-2026-45061 | Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`) | 高危 | npmbudibase | 已审查 | 2026-05-12 00:20 | 2026-06-09 04:15 |
| GHSA-39QR-RC93-VHQM CVE-2026-45047 | Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding | 高危 | Gogithub.com/xddxdd/bird-lg-go | 已审查 | 2026-05-12 00:17 | 2026-06-09 07:49 |
| GHSA-WXXX-GVQV-XP7P CVE-2026-40217 | LiteLLM has a sandbox escape in custom-code guardrail | 高危 | PyPIlitellm | 已审查 | 2026-05-12 00:17 | 2026-05-12 00:17 |
| GHSA-9CCR-R5HG-74GF CVE-2026-45033 | GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor | 高危 | npm@github/copilot | 已审查 | 2026-05-12 00:16 | 2026-06-09 18:56 |