检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2887-F3V6-6RJF CVE-2023-42345 | Alkacon OpenCms is vulnerable to XSS via updateModelGroups.jsp | 中危 | Mavenorg.opencms:opencms-core | 已审查 | 2026-05-08 14:32 | 2026-05-14 21:04 |
| GHSA-935G-9RQ5-Q95C CVE-2026-8115 | short-video-maker has a path traversal vulnerability |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmshort-video-maker |
| 已审查 |
| 2026-05-08 08:31 |
| 2026-05-13 09:37 |
| GHSA-MMPC-XJXR-5HF8 CVE-2026-40214 | OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer | 中危 | PyPIopenstack-cyborg | 已审查 | 2026-05-08 08:31 | 2026-05-13 09:37 |
| GHSA-MM7J-MHHJ-HJ36 CVE-2026-40213 | OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints | 高危 | PyPIopenstack-cyborg | 已审查 | 2026-05-08 08:31 | 2026-05-13 09:37 |
| GHSA-XV59-967R-8726 CVE-2026-44662 | rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding | 中危 | crates.ioopenssl | 已审查 | 2026-05-08 06:33 | 2026-05-16 07:46 |
| GHSA-39J6-4867-GG4W CVE-2026-44661 | utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol | 中危 | PyPIutcp-http | 已审查 | 2026-05-08 06:32 | 2026-05-16 07:45 |
| GHSA-V7QW-HX66-4W9X | netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables | 高危 | PyPInetbox-data-flows | 已审查 | 2026-05-08 06:31 | 2026-05-08 06:31 |
| GHSA-J7H9-2JH7-G967 | mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening | 高危 | npmmcp-ssh-tool | 已审查 | 2026-05-08 05:45 | 2026-05-08 05:45 |
| GHSA-XHRW-5QXX-JPWR CVE-2026-44641 | Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install | 高危 | PyPIapm-cli | 已审查 | 2026-05-08 05:41 | 2026-05-16 07:51 |
| GHSA-FPW6-HRG5-Q5X5 | ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI | 高危 | Gogithub.com/lin-snow/ech0 | 已审查 | 2026-05-08 05:34 | 2026-07-21 22:37 |
| GHSA-P64J-F4X9-WQ66 | Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft | 高危 | Gogithub.com/lin-snow/Ech0 | 已审查 | 2026-05-08 05:30 | 2026-05-08 05:30 |
| GHSA-J3F5-RW74-G4RV CVE-2026-8088 | OSGeo GDAL vulnerable to out-of-bounds read | 低危 | PyPIGDAL | 已审查 | 2026-05-08 05:30 | 2026-05-13 00:29 |
| GHSA-H9RH-5FFH-H669 CVE-2026-8087 | OSGeo GDAL vulnerable to heap-based buffer overflow | 低危 | PyPIGDAL | 已审查 | 2026-05-08 05:30 | 2026-05-13 00:29 |
| GHSA-R7C9-7PJQ-HMM8 CVE-2026-44742 | Postorius is vulnerable to XSS | 高危 | PyPIpostorius | 已审查 | 2026-05-08 05:30 | 2026-05-13 00:20 |
| GHSA-8MC6-XJPR-H98X | Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo | 高危 | Gogithub.com/lin-snow/ech0 | 已审查 | 2026-05-08 05:28 | 2026-05-08 05:28 |
| GHSA-PJ6Q-4VQ4-R8CG | Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count | 中危 | Gogithub.com/lin-snow/Ech0 | 已审查 | 2026-05-08 05:23 | 2026-05-08 05:23 |
| GHSA-RGJ7-VG8V-J4WR | Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation | 中危 | Gogithub.com/lin-snow/ech0 | 已审查 | 2026-05-08 05:21 | 2026-05-08 05:21 |
| GHSA-3V85-FQVH-7RXF | Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers | 中危 | Gogithub.com/lin-snow/Ech0 | 已审查 | 2026-05-08 05:18 | 2026-05-08 05:18 |
| GHSA-RJ4G-RQGH-RX9H | Ech0 comment model's Email field returned on public /api/comments endpoints | 中危 | Gogithub.com/lin-snow/Ech0 | 已审查 | 2026-05-08 05:16 | 2026-05-08 05:16 |
| GHSA-Q6MH-RQWH-G786 CVE-2026-44523 | Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery | 严重 | Gogithub.com/enchant97/note-mark/backend | 已审查 | 2026-05-08 05:08 | 2026-05-16 07:45 |
| GHSA-G49P-4QXJ-88V3 CVE-2026-44522 | Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution | 高危 | Gogithub.com/enchant97/note-mark/backend | 已审查 | 2026-05-08 05:06 | 2026-05-16 07:45 |
| GHSA-H4FW-6R7F-W494 | Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy | 低危 | Packagistweb-auth/webauthn-framework | 已审查 | 2026-05-08 05:05 | 2026-05-08 05:05 |
| GHSA-CWFQ-RFCR-8HMP | Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs | 严重 | crates.iozebrad | 已审查 | 2026-05-08 05:02 | 2026-05-08 05:02 |
| GHSA-GQ4H-3GRW-2RHV CVE-2026-44497 | Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer | 严重 | crates.iozebra-script+1 | 已审查 | 2026-05-08 04:56 | 2026-05-13 21:28 |
| GHSA-438Q-JX8F-CCCV CVE-2026-44500 | Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers | 中危 | crates.iozebra-chain+2 | 已审查 | 2026-05-08 04:55 | 2026-05-13 21:28 |