检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3R34-VQ8M-39GH CVE-2026-44304 | Lemur: LDAP Filter Injection enables post-authentication privilege escalation | 高危 | PyPIlemur | 已审查 | 2026-05-07 03:16 | 2026-05-14 00:41 |
| GHSA-VR7C-R5GJ-J3W5 CVE-2026-44305 | Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIlemur |
| 已审查 |
| 2026-05-07 02:48 |
| 2026-05-14 00:41 |
| GHSA-VRQV-52X7-RM4V | Kimai's Twig function config() leaks server-wide secrets (LDAP bind password, SAML SP private key) via invoice/export templates | 中危 | Packagistkimai/kimai | 已审查 | 2026-05-07 02:42 | 2026-05-07 02:42 |
| GHSA-2V93-VP82-CJV8 CVE-2026-6863 | Velocidex Velociraptor has an Incorrect Authorization issue | 中危 | Gowww.velocidex.com/golang/velociraptor | 已审查 | 2026-05-07 02:30 | 2026-05-11 22:58 |
| GHSA-9G2Q-W3W2-VF7Q | Kimai has Missing Voter Check that Allows Cross-Team Timesheet Manipulation | 中危 | Packagistkimai/kimai | 已审查 | 2026-05-07 02:28 | 2026-05-07 02:28 |
| GHSA-V2FC-QM4H-8HQV CVE-2026-79771 | Nokogiri XSLT transform has a memory leak | 中危 | RubyGemsnokogiri | 已审查 | 2026-05-07 02:27 | 2026-09-02 22:42 |
| GHSA-C4RQ-3M3G-8WGX CVE-2026-79770 | Nokogiri CSS selector tokenizer has regular expression backtracking | 高危 | RubyGemsnokogiri | 已审查 | 2026-05-07 02:24 | 2026-09-02 22:43 |
| GHSA-8P33-Q827-GHJ5 CVE-2026-44232 | dssrf: every IPv6 category bypasses is_url_safe | 高危 | npmdssrf | 已审查 | 2026-05-07 02:13 | 2026-06-19 06:54 |
| GHSA-2528-JW5Q-WW88 CVE-2024-27354 | phpseclib: guardrails needed on isPrime and randomPrime | 高危 | Packagistphpseclib/phpseclib | 已审查 | 2026-05-07 01:57 | 2026-05-07 01:57 |
| GHSA-33M5-HQP9-97PW CVE-2026-44012 | Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure | 高危 | Packagistcraftcms/cms | 已审查 | 2026-05-07 01:54 | 2026-05-14 00:29 |
| GHSA-C3GC-9PF2-84GG CVE-2026-44226 | PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI | 中危 | PyPIpyload-ng | 已审查 | 2026-05-07 01:54 | 2026-05-13 22:18 |
| GHSA-QRGM-P9W5-RRFW CVE-2026-44011 | Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior | 高危 | Packagistcraftcms/cms | 已审查 | 2026-05-07 01:54 | 2026-05-14 00:29 |
| GHSA-GJ2P-P9M4-C8GW CVE-2026-44010 | Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure | 高危 | Packagistcraftcms/cms | 已审查 | 2026-05-07 01:49 | 2026-05-14 00:29 |
| GHSA-4C35-WCG5-MM9H | next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys | 中危 | npmnext-intl | 已审查 | 2026-05-07 01:34 | 2026-05-07 01:34 |
| GHSA-R27J-894H-3W3P | mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true` | 低危 | npmicu-minify | 已审查 | 2026-05-07 01:32 | 2026-05-07 01:32 |
| GHSA-XX64-WWV2-HCQQ | astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks | 低危 | crates.ioastral-tokio-tar | 已审查 | 2026-05-07 01:26 | 2026-05-07 01:26 |
| GHSA-FP55-JW48-C537 | astral-tokio-tar is Vulnerable to PAX Header Desynchronization | 中危 | crates.ioastral-tokio-tar | 已审查 | 2026-05-07 01:26 | 2026-05-07 01:26 |
| GHSA-V5C3-6WVC-PC2Q CVE-2026-42339 | QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 | 高危 | Gogithub.com/QuantumNous/new-api | 已审查 | 2026-05-07 01:23 | 2026-05-13 21:38 |
| GHSA-HQWM-7X7X-8379 CVE-2026-42283 | DevSpace UI Server WebSocket CheckOrigin does not validate source | 高危 | Gogithub.com/loft-sh/devspace | 已审查 | 2026-05-07 01:05 | 2026-05-15 04:51 |
| GHSA-8QJV-JJ2Q-X832 CVE-2026-42280 | Auth.js SDK has Improper Permission Checking | 高危 | npmauth0-js | 已审查 | 2026-05-07 01:05 | 2026-06-09 07:41 |
| GHSA-4PVG-PRR3-9CXR CVE-2026-42238 | Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore | 严重 | Gogithub.com/0xJacky/nginx-ui | 已审查 | 2026-05-07 01:03 | 2026-05-07 01:03 |
| GHSA-Q4W7-56HR-83RM CVE-2026-42223 | Nginx-UI Settings API Exposes Protected Secrets | 中危 | Gogithub.com/0xJacky/nginx-ui | 已审查 | 2026-05-07 01:01 | 2026-05-07 01:01 |
| GHSA-MXQH-Q9H6-V8PQ CVE-2026-42222 | Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover | 高危 | Gogithub.com/0xJacky/nginx-ui | 已审查 | 2026-05-07 00:59 | 2026-05-07 00:59 |
| GHSA-H27V-PH7W-M9FP CVE-2026-42221 | Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim | 高危 | Gogithub.com/0xJacky/Nginx-UI | 已审查 | 2026-05-07 00:59 | 2026-05-07 00:59 |
| GHSA-7GMJ-67G7-PHM9 CVE-2026-42184 | Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands | 中危 | crates.iotauri | 已审查 | 2026-05-07 00:58 | 2026-06-09 07:41 |