检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X757-HV69-JR45 CVE-2024-7959 | Withdrawn Advisory: Open WebUI has SSRF in /openai/models 已撤回 | 高危 | PyPIopen-webui | 已审查 | 2025-03-20 20:32 | 2026-09-03 04:49 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-4VMG-RW8F-92F9 CVE-2024-7804 |
Withdrawn Advisory: PyTorch deserialization vulnerability 已撤回 |
| 严重 |
PyPItorch |
| 已审查 |
| 2025-03-20 20:32 |
| 2025-04-02 21:31 |
| GHSA-PQWR-PHVV-V49F CVE-2024-7039 | Withdrawn Advisory: Open WebUI Allows Admin Deletion via API Endpoint 已撤回 | 高危 | PyPIopen-webui | 已审查 | 2025-03-20 20:32 | 2026-09-03 04:49 |
| GHSA-CRH6-PJ8C-XRHC CVE-2024-7034 | Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint 已撤回 | 中危 | PyPIopen-webui | 已审查 | 2025-03-20 20:32 | 2026-09-03 04:49 |
| GHSA-CFVQ-FJ53-J2C7 CVE-2024-7040 | Withdrawn Advisory: Open WebUI Access Control 已撤回 | 中危 | PyPIopen-webui | 已审查 | 2025-03-20 20:32 | 2026-09-03 04:49 |
| GHSA-3P9Q-7W63-3F8Q CVE-2024-7033 | Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint 已撤回 | 中危 | PyPIopen-webui | 已审查 | 2025-03-20 20:32 | 2026-09-02 22:29 |
| GHSA-XQGJ-R6XV-9CW4 CVE-2024-10096 | Withdrawn Advisory: Dask Vulnerable to Command Injection 已撤回 | 严重 | PyPIdask | 已审查 | 2025-03-20 20:32 | 2025-03-28 23:35 |
| GHSA-3RW8-4XRQ-3F7P | Duplicate Advisory: Uptime Kuma ReDoS vulnerability 已撤回 | 中危 | npmuptime-kuma | 已审查 | 2025-03-18 05:30 | 2025-08-07 22:02 |
| GHSA-3PWP-2FQJ-6G2P | Duplicate Advisory: Qiskit allows arbitrary code execution decoding QPY format versions < 13 已撤回 | 严重 | PyPIqiskit | 已审查 | 2025-03-14 23:32 | 2025-03-15 03:56 |
| GHSA-323W-6P85-26FR | Duplicate Advisory: Plenti - Code Injection - Denial of Services 已撤回 | 中危 | Gogithub.com/plentico/plenti | 已审查 | 2025-03-13 02:32 | 2025-03-13 05:58 |
| GHSA-5478-V2W6-C6Q7 | Duplicate Advisory: Keras arbitrary code execution vulnerability 已撤回 | 高危 | PyPIkeras | 已审查 | 2025-03-11 17:30 | 2025-03-12 04:07 |
| GHSA-2FH4-GPCH-VQV4 | Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch 已撤回 | 中危 | PyPIpicklescan | 已审查 | 2025-03-10 20:30 | 2025-03-11 02:31 |
| GHSA-W6MR-MJ53-X258 | Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch 已撤回 | 中危 | PyPIpicklescan | 已审查 | 2025-03-10 20:30 | 2025-03-11 02:25 |
| GHSA-3JXR-23PH-C89G | Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI 已撤回 | 高危 | Mavenorg.wildfly.core:wildfly-elytron-integration | 已审查 | 2025-03-05 02:33 | 2026-06-30 11:35 |
| GHSA-HW34-RQC5-H2GM | Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis 已撤回 | 中危 | PyPIpicklescan | 已审查 | 2025-03-04 05:30 | 2025-03-04 06:23 |
| GHSA-VR75-HJH9-7FR6 | Duplicate Advisory: Remote Code Execution via Malicious Pickle File Bypassing Static Analysis 已撤回 | 中危 | PyPIpicklescan | 已审查 | 2025-03-04 02:31 | 2025-03-04 04:05 |
| GHSA-5MWF-688X-MR7X | Duplicate Advisory: Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171 已撤回 | 低危 | RubyGemsnokogiri | 已审查 | 2025-02-20 06:17 | 2025-03-11 06:39 |
| GHSA-RQ4W-CJRR-H8W8 | Duplicate Advisory: Keycloak allows Incorrect Assignment of an Organization to a User 已撤回 | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2025-02-17 23:32 | 2025-03-11 05:31 |
| GHSA-XG2H-7CXJ-3GVH CVE-2024-57000 | Withdrawn Advisory: Command injection in Ray 已撤回 | 严重 | PyPIray | 已审查 | 2025-02-12 08:32 | 2025-02-15 05:30 |
| GHSA-QV5F-57GW-VX3H | Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard Stack 已撤回 | 高危 | NuGetOPCFoundation.NetStandard.Opc.Ua | 已审查 | 2025-02-11 05:31 | 2025-03-04 04:10 |
| GHSA-7WWR-H8CM-9JF7 | Duplicate Advisory: Authentication Bypass by Spoofing in OPC UA .NET Standard Stack 已撤回 | 中危 | NuGetOPCFoundation.NetStandard.Opc.Ua | 已审查 | 2025-02-11 05:31 | 2025-03-04 04:08 |
| GHSA-2HJH-495W-HMXC CVE-2024-57610 | Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts 已撤回 | 中危 | Packagistsylius/sylius | 已审查 | 2025-02-07 02:31 | 2025-02-08 00:37 |
| GHSA-FCRW-MPHX-7CXF | Duplicate Advisory: Wildfly Server Role Based Access Control (RBAC) provider has Improper Access Control 已撤回 | 中危 | Mavenorg.wildfly:wildfly-server | 已审查 | 2025-01-30 23:31 | 2025-02-01 01:34 |
| GHSA-29QP-CRVH-W22M | Withdrawn Advisory: github.com/hashicorp/yamux's DefaultConfig has dangerous defaults causing hung Read 已撤回 | 中危 | Gogithub.com/hashicorp/yamux | 已审查 | 2025-01-30 03:19 | 2025-02-07 01:31 |
| GHSA-8M8M-98C9-VW7Q | Duplicate Advisory: pimcore/customer-data-framework vulnerable to SQL Injection: Hibernate 已撤回 | 中危 | Packagistpimcore/customer-data-framework | 已审查 | 2025-01-28 23:31 | 2025-01-29 03:14 |