检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-C6W6-57JJ-62VH CVE-2026-52822 | Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 08:04 | 2026-07-14 08:04 |
| GHSA-3Q6Q-26VG-V97X CVE-2026-52821 | Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistkimai/kimai |
| 已审查 |
| 2026-07-14 08:03 |
| 2026-07-14 08:03 |
| GHSA-VRR2-G9GH-C3JC CVE-2026-52820 | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 07:55 | 2026-07-14 07:55 |
| GHSA-4M8Q-55QV-9PWP CVE-2026-52819 | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 07:55 | 2026-07-14 07:55 |
| GHSA-PGCC-VFMC-7CW5 CVE-2026-49992 | Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes | 中危 | Packagistkimai/kimai | 已审查 | 2026-07-14 07:55 | 2026-07-14 07:55 |
| GHSA-8F6J-263M-G72X | Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks | 中危 | PyPIapp-store-server-library | 已审查 | 2026-07-14 07:49 | 2026-07-14 07:49 |
| GHSA-XF7X-X43H-RPQH | json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS | 高危 | PyPIjson-repair | 已审查 | 2026-07-14 07:41 | 2026-07-14 07:41 |
| GHSA-C67F-GMXW-MJ93 CVE-2026-47677 | FacturaScripts: Account takeover of any 2FA-enabled user | 严重 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-14 07:35 | 2026-07-14 07:35 |
| GHSA-XV8G-76MX-2RXC CVE-2026-49970 | Laravel-Mediable: path traversal vulnerability in the File::sanitizePath() | 高危 | Packagistplank/laravel-mediable | 已审查 | 2026-07-14 05:31 | 2026-08-14 02:28 |
| GHSA-7XW9-549R-8JRC | DIRAC: SQL injection and lack of access control in PilotManager service | 高危 | PyPIDIRAC | 已审查 | 2026-07-14 02:38 | 2026-07-14 02:38 |
| GHSA-VG99-GR89-QHW9 CVE-2026-61668 | DIRAC: Pilot code downloaded over unverified HTTPS connection | 高危 | PyPIDIRAC | 已审查 | 2026-07-14 02:37 | 2026-07-14 02:37 |
| GHSA-M4M7-4CW8-62J6 CVE-2026-61667 | DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval | 严重 | PyPIDIRAC | 已审查 | 2026-07-14 02:37 | 2026-07-14 02:37 |
| GHSA-H4PC-58CC-HC95 CVE-2026-59955 | Apollo ConfigService access key authentication bypass via raw config file appId parsing | 高危 | Mavencom.ctrip.framework.apollo:apollo | 已审查 | 2026-07-14 02:37 | 2026-07-21 03:16 |
| GHSA-4W3Q-QPFQ-V992 CVE-2026-59954 | Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching | 高危 | Mavencom.ctrip.framework.apollo:apollo | 已审查 | 2026-07-14 02:26 | 2026-07-21 03:16 |
| GHSA-4CHG-4752-W88R CVE-2026-55372 | NukeViet: Pre-authentication SSRF via X-Forwarded-Host | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-07-14 01:58 | 2026-07-14 01:58 |
| GHSA-C9XG-64P9-F2JJ CVE-2026-54065 | NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-07-14 01:55 | 2026-07-14 01:55 |
| GHSA-465G-4Q99-5X86 CVE-2026-54064 | NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-07-14 01:54 | 2026-07-14 01:54 |
| GHSA-W2W5-W2PW-R929 CVE-2026-49259 | NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-07-14 01:22 | 2026-07-14 01:22 |
| GHSA-MXPF-QGG6-V3FF CVE-2026-48118 | NukeViet: Unauthenticated Reflected XSS in Comment Module | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-07-14 01:21 | 2026-07-14 01:21 |
| GHSA-9JPV-C7P4-997X CVE-2026-45579 | DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input | 严重 | PyPIDIRAC | 已审查 | 2026-07-14 01:20 | 2026-07-14 01:20 |
| GHSA-2G9C-VF8H-PRXX CVE-2026-45573 | Decidim: Push subscriptions can be abused for server-side requests | 中危 | RubyGemsdecidim-core | 已审查 | 2026-07-14 01:19 | 2026-07-14 01:19 |
| GHSA-533C-2VH9-4R86 CVE-2026-45572 | Decidim: HTML content blocks allow stored script execution | 中危 | RubyGemsdecidim-core | 已审查 | 2026-07-14 01:18 | 2026-07-14 01:18 |
| GHSA-Q79H-67VX-M9XG CVE-2026-45415 | Decidim: CSV census record endpoints improper authorization | 中危 | RubyGemsdecidim-verifications | 已审查 | 2026-07-14 01:17 | 2026-07-14 01:17 |
| GHSA-R3V7-5X4C-C69Q CVE-2026-45414 | Decidim: JWT-backed authentication can be replayed across organizations | 高危 | RubyGemsdecidim | 已审查 | 2026-07-14 01:16 | 2026-07-14 01:16 |
| GHSA-3MVF-82QP-8QH5 CVE-2026-45378 | Decidim: Verification documents can be downloaded through reusable links | 高危 | RubyGemsdecidim-verifications | 已审查 | 2026-07-14 01:10 | 2026-07-14 01:10 |