检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J5JQ-CR68-V2XX CVE-2026-35445 | Winter: Authenticated backend users can bypass Users controller permission checks | 高危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-12 23:15 | 2026-08-12 23:15 |
| GHSA-5C4F-9PQ9-6C77 CVE-2026-32639 | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistwinter/wn-cms-module |
| 已审查 |
| 2026-08-12 23:14 |
| 2026-08-12 23:14 |
| GHSA-M7JC-G4RC-JMVH CVE-2026-32593 | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax | 中危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-12 22:41 | 2026-08-12 22:41 |
| GHSA-VGP4-2FC4-QFF2 CVE-2026-32258 | Winter: Stored XSS through Editor Settings custom styles | 高危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-12 22:40 | 2026-08-12 22:40 |
| GHSA-V7CF-8GH9-GXMJ CVE-2026-32257 | Winter: Stored XSS through Brand Settings custom styles | 高危 | Packagistwinter/wn-backend-module | 已审查 | 2026-08-12 22:40 | 2026-08-12 22:40 |
| GHSA-GQGW-JGHV-MXWX CVE-2026-9318 | tablib: Stored XSS in the HTML export via unescaped dataset title | 中危 | PyPItablib | 已审查 | 2026-08-12 11:31 | 2026-08-13 03:32 |
| GHSA-9MRH-PW7C-9MQM CVE-2026-62902 | Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability | 中危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 03:55 | 2026-08-12 03:55 |
| GHSA-VG44-H755-9HW7 CVE-2026-62871 | Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 03:46 | 2026-08-12 03:46 |
| GHSA-FX4Q-GJRX-2JW6 CVE-2026-62897 | Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 03:36 | 2026-08-12 03:36 |
| GHSA-GG8C-3338-XW2F CVE-2026-70354 | Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 03:24 | 2026-08-12 03:24 |
| GHSA-9MR8-PWPW-3J2W CVE-2026-62909 | Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability | 中危 | NuGetMicrosoft.NETCore.App.Runtime.linux-arm+7 | 已审查 | 2026-08-12 03:04 | 2026-08-12 03:04 |
| GHSA-JQHP-238X-QHGF CVE-2026-62886 | Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 02:58 | 2026-08-12 02:58 |
| GHSA-M93F-WJ8C-RP8P CVE-2026-62901 | Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability | 高危 | NuGetMicrosoft.NETCore.App.Runtime.linux-arm+10 | 已审查 | 2026-08-12 02:53 | 2026-08-12 02:53 |
| GHSA-R6MH-95JW-G7QG CVE-2026-62899 | Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability | 中危 | NuGetMicrosoft.NETCore.App.Runtime.linux-arm+7 | 已审查 | 2026-08-12 02:40 | 2026-08-12 02:40 |
| GHSA-C494-M2FQ-59MX CVE-2026-62898 | Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability | 高危 | NuGetMicrosoft.NETCore.App.Runtime.win-arm64+2 | 已审查 | 2026-08-12 02:28 | 2026-08-12 02:34 |
| GHSA-87FV-VQQR-M4JR CVE-2026-73080 | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle | 严重 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-08-11 23:58 | 2026-08-11 23:58 |
| GHSA-H784-HPJP-2RRM | Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:04 |
| GHSA-CC2G-26RW-G997 | Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:06 |
| GHSA-9W6W-8X3C-HFQP | Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:19 |
| GHSA-4HC4-QJFX-WJF3 | Duplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element 已撤回 | 严重 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:11 |
| GHSA-W36C-QXRQ-V7FW | Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:07 |
| GHSA-2P2V-3MJG-GFPF | Duplicate Advisory: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:03 |
| GHSA-4JJW-PWVW-Q6W3 | Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint 已撤回 | 中危 | npmnuxt | 已审查 | 2026-08-11 23:32 | 2026-08-13 22:18 |
| GHSA-4F2F-JR2M-J7P4 | Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool 已撤回 | 高危 | Packagisttypo3/cms-core | 已审查 | 2026-08-11 17:32 | 2026-09-02 05:30 |
| GHSA-VHH6-V828-X62F CVE-2026-58230 | SAP Approuter has an Information Disclosure vulnerability | 高危 | npm@sap/approuter | 已审查 | 2026-08-11 11:31 | 2026-09-02 05:20 |