检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P46P-7PMJ-M34F CVE-2026-38993 | Cockpit is vulnerable to directory traversal | 中危 | Packagistcockpit-hq/cockpit | 已审查 | 2026-04-30 02:31 | 2026-05-07 07:05 |
| GHSA-J2RX-4JG9-79MW CVE-2026-38991 | Cockpit Vulnerable to Unrestricted Upload of File with Dangerous Type |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistcockpit-hq/cockpit |
| 已审查 |
| 2026-04-30 02:31 |
| 2026-05-07 07:11 |
| GHSA-VC24-J8C5-2VW4 CVE-2026-41483 | OpenTelemetry.Resources.Azure has an unbounded HTTP response body read | 中危 | NuGetOpenTelemetry.Resources.Azure | 已审查 | 2026-04-30 02:30 | 2026-05-09 03:32 |
| GHSA-3GXM-WFJX-M847 CVE-2026-42052 | beets has a Cross-site Scripting vulnerability | 中危 | PyPIbeets | 已审查 | 2026-04-30 02:29 | 2026-06-24 08:30 |
| GHSA-JP6G-G3V3-6GVF CVE-2026-42525 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin has an open redirect vulnerability | 中危 | Mavenorg.jenkins-ci.plugins:azure-ad | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:56 |
| GHSA-FM6C-RHCF-7439 CVE-2026-38992 | Cockpit is vulnerable to arbitrary code execution | 严重 | Packagistcockpit-hq/cockpit | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:57 |
| GHSA-F8H4-46XV-H7JJ CVE-2026-42524 | Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file | 高危 | Mavenorg.jenkins-ci.plugins:htmlpublisher | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:52 |
| GHSA-WG26-8WMJ-CF9P CVE-2026-42522 | Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test | 中危 | Mavenorg.jenkins-ci.plugins:github-branch-source | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:48 |
| GHSA-W22P-4X9F-486V CVE-2026-42523 | Jenkins GitHub Plugin has an XSS vulnerability | 严重 | Mavencom.coravy.hudson.plugins.github:github | 已审查 | 2026-04-29 23:30 | 2026-08-15 03:48 |
| GHSA-P334-GFHQ-C7W6 CVE-2026-42519 | Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths | 中危 | Mavenorg.jenkins-ci.plugins:script-security | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:44 |
| GHSA-P2RF-WPXJ-MX2G CVE-2026-42520 | Jenkins Credentials Binding Plugin has a path traversal vulnerability | 高危 | Mavenorg.jenkins-ci.plugins:credentials-binding | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:45 |
| GHSA-JP9R-MMHW-VFF3 CVE-2026-42521 | Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors | 中危 | Mavenorg.jenkins-ci.plugins:matrix-auth | 已审查 | 2026-04-29 23:30 | 2026-05-07 06:47 |
| GHSA-WG35-8JPF-2XV3 CVE-2026-22741 | Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. | 低危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-04-29 20:33 | 2026-07-03 05:23 |
| GHSA-6P4F-WCWH-5VVM CVE-2026-22745 | Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-04-29 20:33 | 2026-05-07 06:30 |
| GHSA-5843-P793-GHMM CVE-2026-22740 | Spring Framework DoS with Multipart Temp Files in WebFlux | 中危 | Mavenorg.springframework:spring-webflux | 已审查 | 2026-04-29 20:33 | 2026-07-03 05:44 |
| GHSA-H4HV-92PP-PCJG CVE-2026-42615 | CyberChef has a Cross-site Scripting issue | 高危 | npmcyberchef | 已审查 | 2026-04-29 14:33 | 2026-05-07 06:09 |
| GHSA-J7RW-325J-2RMX | Duplicate Advisory: Grav has Insecure Deserialization in File Cache 已撤回 | 低危 | Packagistgetgrav/grav | 已审查 | 2026-04-29 08:30 | 2026-05-07 05:57 |
| GHSA-R727-5PF6-47R2 CVE-2026-33467 | Elastic Package Registry has Improper Verification of Cryptographic Signature | 中危 | Gogithub.com/elastic/package-registry | 已审查 | 2026-04-29 08:30 | 2026-05-07 05:56 |
| GHSA-GW2X-MFWR-H46P CVE-2026-7303 | xxl-job has a Resource Injection issue | 低危 | Mavencom.xuxueli:xxl-job-admin | 已审查 | 2026-04-29 08:30 | 2026-05-07 05:56 |
| GHSA-88HF-WF7H-7W4M CVE-2026-41310 | OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure | 中危 | NuGetOpenTelemetry.Exporter.Zipkin | 已审查 | 2026-04-29 07:23 | 2026-05-09 03:32 |
| GHSA-HRMW-QPRP-WGMC CVE-2026-40296 | PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer | 中危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-04-29 06:57 | 2026-05-09 03:32 |
| GHSA-VP29-5652-4FW9 CVE-2026-35579 | CoreDNS has TSIG authentication bypass on gRPC and QUIC transports | 高危 | Gogithub.com/coredns/coredns | 已审查 | 2026-04-29 06:54 | 2026-05-08 23:30 |
| GHSA-6WPP-88CP-7Q68 CVE-2026-35453 | PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer | 中危 | Packagistphpoffice/phpspreadsheet | 已审查 | 2026-04-29 06:50 | 2026-05-08 23:29 |
| GHSA-QHMP-Q7XH-99RH CVE-2026-33190 | CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC | 高危 | Gogithub.com/coredns/coredns | 已审查 | 2026-04-29 06:46 | 2026-05-08 23:28 |
| GHSA-H8MM-C463-WJQ3 CVE-2026-33489 | CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass) | 高危 | Gogithub.com/coredns/coredns | 已审查 | 2026-04-29 06:44 | 2026-05-08 23:28 |