检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FG3J-5W9G-HMG7 CVE-2026-6970 | authd: Primary group ID is incorrectly set to value of UID | 高危 | Gogithub.com/canonical/authd | 已审查 | 2026-05-06 06:04 | 2026-05-06 06:04 |
| GHSA-6RVW-7P8V-MJFQ CVE-2026-43881 | AVideo: Unauthenticated User Enumeration in objects/users.json.php via isCompany Parameter Allows Bypass of the Admin-Only Listing Restriction |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistwwbn/avideo |
| 已审查 |
| 2026-05-06 06:02 |
| 2026-05-13 22:20 |
| GHSA-W2JH-77FQ-7GP8 CVE-2026-42348 | OpAMP client reads unbounded HTTP response bodies | 中危 | NuGetOpenTelemetry.OpAmp.Client | 已审查 | 2026-05-06 05:57 | 2026-05-14 00:27 |
| GHSA-5HGJ-7GM9-CFF5 CVE-2026-43880 | AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Enables Phishing from the Site’s Legitimate From Address | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 05:56 | 2026-05-13 22:20 |
| GHSA-FW8G-CG8F-9J28 CVE-2026-44903 | Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display | 中危 | Gogithub.com/prometheus/prometheus | 已审查 | 2026-05-06 05:53 | 2026-06-09 07:34 |
| GHSA-3H96-34P3-XM76 | GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens | 中危 | RubyGemsgraphql | 已审查 | 2026-05-06 05:51 | 2026-05-06 05:51 |
| GHSA-V2V4-37R5-5V8G CVE-2026-42338 | ip-address has XSS in Address6 HTML-emitting methods | 中危 | npmip-address | 已审查 | 2026-05-06 05:50 | 2026-05-14 00:27 |
| GHSA-WP38-WHX3-XFFH CVE-2026-43879 | AVideo has Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 05:49 | 2026-05-13 22:20 |
| GHSA-WQCW-G35J-J578 CVE-2026-42541 | Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call | 中危 | Gogithub.com/kubewarden/kubewarden-controller | 已审查 | 2026-05-06 05:49 | 2026-05-14 00:27 |
| GHSA-WPG9-53FQ-2R8H CVE-2026-42334 | Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection | 高危 | npmmongoose | 已审查 | 2026-05-06 05:48 | 2026-05-15 04:53 |
| GHSA-XP3W-R5P5-63RR CVE-2026-42327 | rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs | 高危 | crates.ioopenssl | 已审查 | 2026-05-06 05:46 | 2026-05-16 07:45 |
| GHSA-Q8X4-X7MP-5VG2 CVE-2026-32688 | Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion | 高危 | Hexplug_cowboy | 已审查 | 2026-05-06 05:46 | 2026-05-06 05:46 |
| GHSA-W8CG-7JCJ-4VV2 CVE-2026-42611 | Grav is Vulnerable to Stored XSS via Tag Injection | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:36 | 2026-05-13 21:52 |
| GHSA-3446-6MGW-F79P | Grav is Vulnerable to XXE via SVG Upload | 中危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:35 | 2026-05-06 05:35 |
| GHSA-HMCX-CH82-3FV2 CVE-2026-42608 | Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:34 | 2026-05-13 21:52 |
| GHSA-54W4-233H-X86G CVE-2026-42997 | OpenStack Ironic has an Incorrect Resource Transfer Between Spheres | 高危 | PyPIironic-python-agent | 已审查 | 2026-05-06 05:31 | 2026-05-09 07:07 |
| GHSA-RR73-568V-28F8 CVE-2026-42609 | Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:29 | 2026-05-13 21:52 |
| GHSA-GWFR-JFJF-92VV CVE-2026-7317 | Grav has Insecure Deserialization in File Cache | 低危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:29 | 2026-05-08 23:36 |
| GHSA-VJ3M-2G9H-VM4P | Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass | 严重 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:29 | 2026-05-06 05:29 |
| GHSA-9695-8FR9-HW5Q CVE-2026-42612 | Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event Attributes | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:27 | 2026-05-13 21:52 |
| GHSA-3F29-PQWF-V4J4 CVE-2026-42610 | Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass | 中危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:26 | 2026-05-13 21:52 |
| GHSA-PXM6-MHXR-Q4MJ CVE-2026-42613 | Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups/access | 严重 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:26 | 2026-05-13 21:52 |
| GHSA-C2Q3-P4JR-C55F CVE-2026-42842 | Grav Vulnerable to XSS via Taxonomy Field Values in Admin Panel | 中危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:24 | 2026-05-13 22:04 |
| GHSA-R7FX-8G49-7HHR CVE-2026-42841 | Grav CMS vulnerable to stored XSS via Markdown media attribute() action | 中危 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:24 | 2026-05-13 21:52 |
| GHSA-W48R-JPPP-RCFW CVE-2026-42607 | Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature | 严重 | Packagistgetgrav/grav | 已审查 | 2026-05-06 05:21 | 2026-05-13 21:50 |