检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-767H-63J4-5226 CVE-2026-45377 | Decidim: Private exports can be downloaded through reusable links | 中危 | RubyGemsdecidim-core | 已审查 | 2026-07-14 01:00 | 2026-07-14 01:00 |
| GHSA-JVQQ-CVH4-XM37 CVE-2026-45376 | Decidim: Admin user search allows SQL injection through similarity-based sorting |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
RubyGemsdecidim-admin |
| 已审查 |
| 2026-07-14 00:59 |
| 2026-07-14 00:59 |
| GHSA-86FH-W43W-338C CVE-2026-45330 | Decidim: Verification admins can access supplied IDs from other organizations | 中危 | RubyGemsdecidim-verifications | 已审查 | 2026-07-14 00:54 | 2026-07-14 00:54 |
| GHSA-VQ6J-HJ8W-7V39 CVE-2026-45086 | Decidim: Forms admin question editor lacks authorization | 中危 | RubyGemsdecidim-demographics | 已审查 | 2026-07-14 00:51 | 2026-07-14 00:51 |
| GHSA-JXPJ-9J24-W337 CVE-2025-32781 | Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center | 中危 | Mavencom.ctrip.framework.apollo:apollo | 已审查 | 2026-07-14 00:47 | 2026-07-21 03:16 |
| GHSA-RWCV-WHM8-FMXM CVE-2024-27091 | GeoNode: Stored XSS to full account takeover | 中危 | PyPIgeonode | 已审查 | 2026-07-14 00:44 | 2026-07-14 00:44 |
| GHSA-997V-R4V7-9F3G CVE-2026-15529 | PyOD persistence.load deserializes untrusted artifacts before validation | 中危 | PyPIpyod | 已审查 | 2026-07-13 14:31 | 2026-09-04 03:19 |
| GHSA-QV9R-C865-CP47 CVE-2026-49844 | Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization | 中危 | Mavenorg.apache.logging.log4j:log4j-api | 已审查 | 2026-07-11 08:31 | 2026-08-14 02:28 |
| GHSA-G936-7JQJ-MWV8 | TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation | 严重 | Gogithub.com/almeidapaulopt/tsdproxy | 已审查 | 2026-07-11 05:43 | 2026-07-11 05:43 |
| GHSA-FPG8-7664-JC5Q CVE-2026-54174 | melange: Incomplete package integrity verification allows data section substitution | 高危 | Gochainguard.dev/apko+1 | 已审查 | 2026-07-11 05:43 | 2026-07-11 05:43 |
| GHSA-WMG3-H8MF-WGVR CVE-2026-61459 | mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials | 严重 | PyPImcp-server-kubernetes | 已审查 | 2026-07-11 05:32 | 2026-08-13 03:26 |
| GHSA-48RX-C7PG-Q66R CVE-2026-54171 | Excon does not redact additional sensitive/risky headers when following redirects | 中危 | RubyGemsexcon | 已审查 | 2026-07-11 04:37 | 2026-07-22 02:11 |
| GHSA-H4G2-XFMW-Q2C9 | Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset | 高危 | PyPIclauster | 已审查 | 2026-07-11 04:37 | 2026-07-11 04:37 |
| GHSA-RQQ5-2GF9-4W4Q CVE-2026-54163 | Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input | 中危 | RubyGemssecure_headers | 已审查 | 2026-07-11 04:37 | 2026-07-11 04:37 |
| GHSA-56MP-4F3V-FGJ2 CVE-2026-50551 | SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 04:37 | 2026-07-11 04:37 |
| GHSA-M5F5-28QR-9G9R CVE-2026-54159 | prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE | 严重 | Packagistprestashop/ps_facetedsearch | 已审查 | 2026-07-11 04:36 | 2026-07-11 04:36 |
| GHSA-5XFX-XJ4H-5P7R CVE-2026-54158 | SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-07-11 03:34 | 2026-07-11 03:34 |
| GHSA-G5R6-GV6M-F5JV CVE-2026-73498 | mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment | 高危 | PyPImcp-atlassian | 已审查 | 2026-07-11 03:34 | 2026-08-13 05:17 |
| GHSA-WM45-QH3G-V83F | mcp-atlassian: Arbitrary server-side file read via attachment upload | 高危 | PyPImcp-atlassian | 已审查 | 2026-07-11 03:34 | 2026-07-11 03:34 |
| GHSA-XRMC-C5CG-RV7X | SafeInstall agent guard shell parsing can miss raw package execution | 高危 | npmsafeinstall-cli | 已审查 | 2026-07-11 03:34 | 2026-07-11 03:34 |
| GHSA-QV4M-M73M-8HJ7 | NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file) | 高危 | Packagistnotrinos/notrinos-erp | 已审查 | 2026-07-11 03:34 | 2026-07-11 03:34 |
| GHSA-M8GF-V64P-GFMG CVE-2026-54071 | BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py | 高危 | PyPIBabelDOC | 已审查 | 2026-07-11 03:32 | 2026-07-11 03:32 |
| GHSA-M93H-4HW7-5QCM CVE-2026-54088 | File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) | 严重 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-07-11 03:32 | 2026-07-11 03:32 |
| GHSA-99J7-FHR2-XFJ4 | `exploration` was removed from crates.io for malicious code | 严重 | crates.ioexploration | 已审查 | 2026-07-11 03:32 | 2026-07-11 03:32 |
| GHSA-2PPX-66JV-WPW5 CVE-2026-54136 | Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search | 中危 | crates.iowindmill-api | 已审查 | 2026-07-11 03:28 | 2026-07-11 03:28 |