检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G9CM-RXP7-6GV5 CVE-2026-43876 | AVideo: HTML Injection in notifySubscribers.json.php Allows Platform-Branded Phishing Emails to Channel Subscribers | 中危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 03:11 | 2026-05-13 22:19 |
| GHSA-5W8W-26CH-V5CW CVE-2026-43875 | AVideo: Password Hash Leak in MobileManager OAuth Redirect URL Enables Account Takeover |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistwwbn/avideo |
| 已审查 |
| 2026-05-06 03:08 |
| 2026-05-13 22:19 |
| GHSA-GHCV-22JF-VFXM CVE-2026-43874 | AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass | 高危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 03:07 | 2026-05-13 22:19 |
| GHSA-QM9P-P5PW-JRX2 CVE-2026-43873 | AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server | 高危 | Packagistwwbn/avideo | 已审查 | 2026-05-06 02:58 | 2026-05-13 22:19 |
| GHSA-PXHG-7XR2-W7XG CVE-2026-42080 | PPTAgent: Arbitrary File Write via `save_generated_slides` | 中危 | PyPIpptagent | 已审查 | 2026-05-06 02:57 | 2026-05-06 02:57 |
| GHSA-89G2-XW5C-V95P CVE-2026-42079 | PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope | 高危 | PyPIpptagent | 已审查 | 2026-05-06 02:57 | 2026-05-06 02:57 |
| GHSA-HRCW-XC63-G29M CVE-2026-42078 | PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image | 中危 | PyPIpptagent | 已审查 | 2026-05-06 02:55 | 2026-05-06 02:55 |
| GHSA-RFGQ-WGG8-662P CVE-2026-42882 | S3-Proxy has Security Issues in its Resource Path Matching Implementation | 严重 | Gogithub.com/oxyno-zeta/s3-proxy | 已审查 | 2026-05-06 02:52 | 2026-05-13 22:19 |
| GHSA-4V58-8P28-2RQ3 CVE-2026-6967 | awslabs/tough is Missing Delegated Metadata Validation | 高危 | crates.iotough+1 | 已审查 | 2026-05-06 02:46 | 2026-05-06 02:46 |
| GHSA-8M7C-8M39-RV4X CVE-2026-6966 | awslabs/tough Delegated Roles have a Signature Threshold Bypass | 高危 | crates.iotough+1 | 已审查 | 2026-05-06 02:46 | 2026-05-06 02:46 |
| GHSA-CWJ3-VQPP-PMXR | OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes | 高危 | npmopenclaw | 已审查 | 2026-05-06 02:44 | 2026-05-06 02:44 |
| GHSA-R39H-4C2P-3JXP CVE-2026-45004 | OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution | 高危 | npmopenclaw | 已审查 | 2026-05-06 02:43 | 2026-05-19 23:56 |
| GHSA-Q8FF-7FFM-M3R9 CVE-2026-45005 | OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload | 中危 | npmopenclaw | 已审查 | 2026-05-06 02:42 | 2026-05-19 23:56 |
| GHSA-VVVV-983W-R7PV CVE-2026-42565 | @workos/authkit-session has an Open Redirect via state-derived redirect target | 中危 | npm@workos/authkit-session | 已审查 | 2026-05-06 02:42 | 2026-05-13 22:19 |
| GHSA-WV26-88M5-6H59 CVE-2026-42875 | External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore | 中危 | Gogithub.com/external-secrets/external-secrets | 已审查 | 2026-05-06 02:37 | 2026-05-13 22:18 |
| GHSA-7WC8-WVC4-M498 CVE-2026-42874 | Microdot has HTTP response splitting in Response.set_cookie() | 低危 | PyPImicrodot | 已审查 | 2026-05-06 02:35 | 2026-05-13 22:18 |
| GHSA-VXVF-XVM3-P8J5 CVE-2026-43002 | OpenStack Horizon has Incorrect Behavior Order | 中危 | PyPIhorizon | 已审查 | 2026-05-06 02:33 | 2026-05-09 06:19 |
| GHSA-JV4P-MHMP-69VW CVE-2026-7847 | Langchain-Chatchat Uses Insufficiently Random Values | 低危 | PyPIlangchain-chatchat | 已审查 | 2026-05-06 02:33 | 2026-05-09 06:20 |
| GHSA-X229-W2J4-H748 CVE-2026-7846 | Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API | 低危 | PyPIlangchain-chatchat | 已审查 | 2026-05-06 02:33 | 2026-05-09 06:17 |
| GHSA-WMVV-FHM6-W34X CVE-2026-7845 | Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm | 低危 | PyPIlangchain-chatchat | 已审查 | 2026-05-06 02:33 | 2026-05-09 06:16 |
| GHSA-W26R-RMM8-9C29 CVE-2026-5766 | Django has an Improper Handling of Length Parameter Inconsistency | 中危 | PyPIDjango | 已审查 | 2026-05-06 02:33 | 2026-06-06 08:27 |
| GHSA-GX3V-WXFJ-8H24 CVE-2026-7412 | Eclipse BaSyx Java Server SDK vulnerable to Server-Side Request Forgery | 高危 | Mavenorg.eclipse.basyx:basyx.sdk | 已审查 | 2026-05-06 02:33 | 2026-05-12 00:23 |
| GHSA-8GPM-H2MH-36QC CVE-2026-7411 | Eclipse BaSyx Java Server SDK vulnerable to Path Traversal | 严重 | Mavenorg.eclipse.basyx:basyx.sdk | 已审查 | 2026-05-06 02:33 | 2026-05-12 00:22 |
| GHSA-5HRC-GVXJ-W55P CVE-2026-6907 | Django Uses Cache Containing Sensitive Information | 低危 | PyPIDjango | 已审查 | 2026-05-06 02:33 | 2026-06-06 08:27 |
| GHSA-7H2M-M8VJ-598H CVE-2026-35192 | Django Uses Persistent Cookies Containing Sensitive Information | 低危 | PyPIDjango | 已审查 | 2026-05-06 02:33 | 2026-06-06 01:53 |