检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JV4H-J224-23CC CVE-2026-44498 | Zebra's Block Validator Undercounts Coinbase and P2SH Sigops | 严重 | crates.iozebrad | 已审查 | 2026-05-08 04:54 | 2026-05-13 21:28 |
| GHSA-C2RM-G55X-8HR5 CVE-2026-44589 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
npmnuxt-og-image |
| 已审查 |
| 2026-05-08 04:52 |
| 2026-05-16 07:44 |
| GHSA-VF3Q-FRMR-VRR9 CVE-2026-42879 | FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images | 中危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:49 | 2026-06-09 07:53 |
| GHSA-VRXF-VRC4-22P7 CVE-2026-42878 | FacturaScripts Vulnerable to Unauthenticated phpinfo() Disclosure via Installer Endpoint | 中危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:43 | 2026-06-09 07:53 |
| GHSA-R736-2678-FCRX CVE-2026-42877 | FacturaScripts vulnerable to stored XSS via product reference in sales/purchases | 中危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:37 | 2026-06-09 07:53 |
| GHSA-GQ5C-RW37-G46C CVE-2026-27964 | FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation | 低危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:34 | 2026-05-20 00:09 |
| GHSA-Q7F2-RV22-2XGR CVE-2026-27892 | FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download | 中危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:33 | 2026-05-20 00:09 |
| GHSA-3PGC-XQG9-CFR6 CVE-2026-27891 | FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | 高危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-05-08 03:32 | 2026-05-08 03:32 |
| GHSA-J822-46R5-H4QX CVE-2026-36341 | Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint | 中危 | Packagistkrayin/laravel-crm | 已审查 | 2026-05-08 02:30 | 2026-05-13 00:20 |
| GHSA-587P-W43Q-4HJX CVE-2025-63704 | query-parser-string is vulnerable to Prototype Pollution | 严重 | npmquery-string-parser | 已审查 | 2026-05-08 02:30 | 2026-05-13 00:19 |
| GHSA-X72J-HV9F-QQH4 CVE-2025-63703 | parse-ini is vulnerable to Prototype Pollution in index.js() | 严重 | npmparse-ini | 已审查 | 2026-05-08 02:30 | 2026-05-13 00:18 |
| GHSA-VPXX-H23G-GXH2 CVE-2025-65122 | youtube-regex vulnerable to Regex Denial of Service | 高危 | npmyoutube-regex | 已审查 | 2026-05-08 02:30 | 2026-05-13 00:20 |
| GHSA-54PG-9963-V8VG | Compromised version of intercom-client published to npm | 严重 | npmintercom-client | 已审查 | 2026-05-08 01:32 | 2026-05-08 01:32 |
| GHSA-GR3R-CRP5-QRRM | Compromised tag of intercom-php published via GitHub | 严重 | Packagistintercom/intercom-php | 已审查 | 2026-05-08 00:48 | 2026-05-08 00:48 |
| GHSA-J944-W549-3453 CVE-2026-42553 | Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service worker | 高危 | npmcinny | 已审查 | 2026-05-08 00:40 | 2026-06-09 07:47 |
| GHSA-MCFX-4VC6-QGXV CVE-2026-40610 | BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context | 中危 | PyPIbentoml | 已审查 | 2026-05-08 00:39 | 2026-06-09 07:20 |
| GHSA-XV9C-MJW8-79GF CVE-2025-67202 | Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL | 中危 | RubyGemssidekiq-cron | 已审查 | 2026-05-07 23:38 | 2026-05-30 05:45 |
| GHSA-8JH2-3MW6-6PFM CVE-2025-63705 | node-ts-ocr is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js | 高危 | npmnode-ts-ocr | 已审查 | 2026-05-07 23:38 | 2026-05-13 00:18 |
| GHSA-2XX6-QF7X-GRQH CVE-2025-63706 | next-npm-version is vulnerable to Command injection | 严重 | npm@jswork/next-npm-version | 已审查 | 2026-05-07 23:38 | 2026-05-13 00:19 |
| GHSA-J6HH-H3CF-C2HF CVE-2026-41004 | Spring Cloud Config Server Logged Sensitive Information | 中危 | Mavenorg.springframework.cloud:spring-cloud-config-server | 已审查 | 2026-05-07 14:31 | 2026-06-19 06:58 |
| GHSA-86WQ-234Q-R6WG CVE-2026-41002 | Spring Cloud Config Server Susceptible To TOCTOU Attack | 高危 | Mavenorg.springframework.cloud:spring-cloud-config-server | 已审查 | 2026-05-07 14:31 | 2026-06-19 06:56 |
| GHSA-6G23-24MC-HX6X CVE-2026-40982 | Spring Cloud Config vulnerable to Path Traversal | 严重 | Mavenorg.springframework.cloud:spring-cloud-config-server | 已审查 | 2026-05-07 14:31 | 2026-06-11 22:50 |
| GHSA-2MH5-3CW6-HRRQ CVE-2026-40981 | Spring Cloud Config has an Authorization Bypass Through User-Controlled Key | 高危 | Mavenorg.springframework.cloud:spring-cloud-config-server | 已审查 | 2026-05-07 14:31 | 2026-06-11 22:48 |
| GHSA-98H9-4798-4Q5V CVE-2026-44513 | Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components | 高危 | PyPIdiffusers | 已审查 | 2026-05-07 13:31 | 2026-06-06 01:53 |
| GHSA-JFG9-48MV-9QGX CVE-2026-44248 | Netty MQTT: Resource exhaustion in MqttDecoder | 中危 | Mavenio.netty:netty-codec-mqtt | 已审查 | 2026-05-07 13:14 | 2026-05-15 04:41 |