—— |
| 未审查 |
| 2026-08-20 05:30 |
| 2026-08-20 05:30 |
| GHSA-M373-Q23Q-FX37 CVE-2026-16832 | 无摘要 | 高危 | —— | 未审查 | 2026-08-20 05:30 | 2026-08-20 05:30 |
| GHSA-CRVH-7J9H-HJJH CVE-2026-16828 | 无摘要 | 高危 | —— | 未审查 | 2026-08-20 05:30 | 2026-08-20 05:30 |
| GHSA-2MJM-M8VH-843X CVE-2026-16835 | 无摘要 | 严重 | —— | 未审查 | 2026-08-20 05:30 | 2026-08-20 05:30 |
| GHSA-RXJR-6C9Q-H67X CVE-2026-63188 | logto-tunnel serves files outside --experience-path via path traversal | 高危 | npm@logto/tunnel | 已审查 | 2026-08-20 04:24 | 2026-08-20 04:24 |
| GHSA-72X6-4J93-7W86 CVE-2026-61712 | BuildKit has a possible runtime DoS via unbounded group parsing | 低危 | Gogithub.com/moby/buildkit | 已审查 | 2026-08-20 04:24 | 2026-08-20 04:24 |
| GHSA-7236-3392-C5C6 CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | 中危 | Gogithub.com/moby/buildkit | 已审查 | 2026-08-20 04:23 | 2026-08-20 04:23 |
| GHSA-HJWH-XVFW-QRWJ | SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-VWG3-W8W3-PC79 CVE-2026-62673 | Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems | 高危 | Packagistgetgrav/grav | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-C8QC-WF67-342W CVE-2026-61807 | Snipe-IT: Stored DOM XSS via table selected-count IDs | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-R9R3-G9FP-3Q4Q CVE-2026-55703 | Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-3HGV-JR5J-CG9X CVE-2026-55694 | Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-08-20 03:32 |
| GHSA-C6W2-J4WQ-MVWG CVE-2026-55643 | Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-20 03:32 | 2026-09-02 23:27 |
| GHSA-WF6J-GR27-G7CH CVE-2024-45747 | GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates | 高危 | Mavenorg.geoserver:gs-main+2 | 已审查 | 2026-08-20 03:31 | 2026-08-20 03:31 |
| GHSA-WPPF-H75H-6PM6 CVE-2026-54689 | SearXNG MCP Server: Additional hardened-mode SSRF bypasses | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:23 | 2026-08-20 03:23 |
| GHSA-Q87F-QC2R-2GW4 CVE-2026-54688 | SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off) | 中危 | npmmcp-searxng | 已审查 | 2026-08-20 03:23 | 2026-08-20 03:23 |
| GHSA-P77J-G7H5-R2VW | GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4) | 高危 | PyPIgeolens | 已审查 | 2026-08-20 03:22 | 2026-08-20 03:23 |
| GHSA-45PH-GXXR-GWGW CVE-2026-53966 | XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing | 高危 | Mavenorg.xwiki.platform:xwiki-platform-livedata-livetable | 已审查 | 2026-08-20 03:18 | 2026-08-20 03:18 |
| GHSA-7M52-JW36-44R3 CVE-2026-53965 | MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter | 高危 | Packagistmcp/sdk | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |
| GHSA-W47Q-945M-Q9PC CVE-2026-53964 | Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) | 高危 | PyPIdocument-merge-service | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |
| GHSA-2XHG-73J7-RRGX CVE-2026-53957 | Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint | 高危 | npm@contentful/mcp-server+1 | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |
| GHSA-9GMC-JQMH-3RVM CVE-2026-53951 | Copier has a trust-prefix bypass via path traversal that runs tasks unprompted | 高危 | PyPIcopier | 已审查 | 2026-08-20 03:16 | 2026-08-20 03:16 |
| GHSA-VJHX-2CQW-3Q6Q CVE-2026-53941 | Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS | 中危 | Gogithub.com/inspektor-gadget/inspektor-gadget | 已审查 | 2026-08-20 03:16 | 2026-08-20 03:16 |
| GHSA-QWGH-2VCV-G2F7 | block_buffer: panic corrupts inline buffer position | 中危 | crates.ioblock_buffer | 已审查 | 2026-08-20 03:15 | 2026-08-20 03:15 |