检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G7MM-9VX7-JM7H CVE-2026-50141 | Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation | 高危 | Gogo.woodpecker-ci.org/woodpecker/v3 | 已审查 | 2026-07-15 03:00 | 2026-07-15 03:00 |
| GHSA-XRCF-6JH3-GGVX CVE-2026-50006 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Gogithub.com/julien040/anyquery |
| 已审查 |
| 2026-07-15 02:33 |
| 2026-07-15 02:33 |
| GHSA-XW9Q-2MV6-9FR8 CVE-2026-50131 | Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges | 高危 | npm@fedify/fedify+1 | 已审查 | 2026-07-15 02:15 | 2026-07-15 02:15 |
| GHSA-QW5R-PPCG-F8RJ CVE-2026-50125 | MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion | 高危 | Gogithub.com/StacklokLabs/mkp | 已审查 | 2026-07-15 02:09 | 2026-07-15 02:09 |
| GHSA-42J2-W334-QXW7 CVE-2026-50018 | Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions | 中危 | Gogithub.com/SpectoLabs/hoverfly | 已审查 | 2026-07-15 02:04 | 2026-07-15 02:04 |
| GHSA-QRH4-P6V4-MRFG CVE-2026-50013 | Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode | 高危 | Gogithub.com/SpectoLabs/hoverfly | 已审查 | 2026-07-15 02:03 | 2026-07-15 02:03 |
| GHSA-JXR7-MQHW-9P98 CVE-2026-54250 | K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression | 中危 | Gogithub.com/k3s-io/k3s | 已审查 | 2026-07-15 01:54 | 2026-07-15 01:54 |
| GHSA-VVP9-H8P2-XWFC CVE-2025-61670 | Wasmtime: Memory leak in C API with `externref` and `anyref` types | 低危 | crates.iowasmtime-bin+1 | 已审查 | 2026-07-15 01:48 | 2026-07-15 01:48 |
| GHSA-3X7P-V8HJ-XH5M CVE-2026-45710 | FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=` | 低危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-15 01:30 | 2026-07-15 01:30 |
| GHSA-2P5X-4JR6-X5JG CVE-2026-45263 | FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export | 高危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-15 01:18 | 2026-07-15 01:18 |
| GHSA-CV65-7CG8-R623 CVE-2026-45693 | FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents | 高危 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-15 01:12 | 2026-07-15 01:12 |
| GHSA-5QMH-X653-G8QJ CVE-2026-45262 | FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` | 严重 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-15 01:11 | 2026-07-15 01:11 |
| GHSA-WMJ8-9953-VFF5 CVE-2026-44300 | OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection | 高危 | Gogithub.com/opencost/opencost | 已审查 | 2026-07-15 01:07 | 2026-07-15 01:19 |
| GHSA-8G6F-QW9X-4Q6Q CVE-2026-15736 | Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities | 高危 | PyPIsnowflake-sqlalchemy | 已审查 | 2026-07-14 23:32 | 2026-09-04 03:49 |
| GHSA-P8PR-442Q-QF8G | Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework 已撤回 | 中危 | Packagisttypo3/cms-form | 已审查 | 2026-07-14 23:32 | 2026-09-01 03:53 |
| GHSA-58HV-7753-XMFQ CVE-2026-12482 | Keras: tar extraction permits symlink-based path traversal | 低危 | PyPIkeras | 已审查 | 2026-07-14 14:31 | 2026-08-08 04:32 |
| GHSA-8M85-WQG7-C529 CVE-2026-27690 | SAP Approuter Vulnerable to HTTP Request Smuggling | 严重 | npm@sap/approuter | 已审查 | 2026-07-14 11:31 | 2026-09-02 05:20 |
| GHSA-44P5-3M5G-VFHJ CVE-2026-44745 | SAP Approuter has an Open Redirect vulnerability | 高危 | npm@sap/approuter | 已审查 | 2026-07-14 11:31 | 2026-09-02 05:20 |
| GHSA-RW46-QG69-VG6H CVE-2026-52828 | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:34 | 2026-07-14 08:34 |
| GHSA-V8HX-4VX8-WC96 CVE-2026-52827 | Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP | 高危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:33 | 2026-07-14 08:33 |
| GHSA-MR4R-HCGX-8P4H CVE-2026-62240 | crewai-tools SSRF redirect bypass exposes internal services | 高危 | PyPIcrewai-tools | 已审查 | 2026-07-14 08:31 | 2026-09-04 03:44 |
| GHSA-2XGG-2X8H-8XW4 CVE-2026-52826 | Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:09 | 2026-07-14 08:09 |
| GHSA-XV4R-4885-GWPG CVE-2026-52825 | Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:09 | 2026-07-14 08:09 |
| GHSA-JR9P-4H4J-6C58 CVE-2026-52824 | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover | 严重 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:07 | 2026-07-14 08:07 |
| GHSA-R8VR-M544-QH4H CVE-2026-52823 | Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:05 | 2026-07-14 08:05 |