检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-65P8-9433-JPCP CVE-2026-52762 | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates | 高危 | Packagistyeswiki/yeswiki | 已审查 | 2026-07-10 04:54 | 2026-07-10 04:54 |
| GHSA-PQPW-CVM4-8MV9 CVE-2026-53769 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
RubyGemsavo |
| 已审查 |
| 2026-07-10 04:54 |
| 2026-07-10 04:54 |
| GHSA-W9MX-XMG4-GC4R CVE-2026-53932 | laravel-backup-restore has an OS Command Injection during database restore | 高危 | Packagistwnx/laravel-backup-restore | 已审查 | 2026-07-10 04:52 | 2026-07-10 04:52 |
| GHSA-339V-266X-79XR CVE-2026-53602 | nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate | 中危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-10 04:52 | 2026-07-10 04:52 |
| GHSA-382C-VX95-W3P5 | Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data | 中危 | npm@jsonbored/gittensory-mcp | 已审查 | 2026-07-09 21:44 | 2026-07-09 21:44 |
| GHSA-HM42-Q32M-VJ4F CVE-2026-53760 | Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests | 中危 | Packagistadmidio/admidio | 已审查 | 2026-07-09 21:44 | 2026-07-09 21:44 |
| GHSA-86VW-X4WW-X467 CVE-2026-56382 | Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview | 高危 | Packagistcraftcms/cms | 已审查 | 2026-07-09 21:44 | 2026-08-07 05:41 |
| GHSA-C43V-4CR8-6MVP CVE-2026-56394 | Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read | 低危 | Packagistcraftcms/cms | 已审查 | 2026-07-09 21:44 | 2026-08-07 05:58 |
| GHSA-9PMC-P236-855H CVE-2026-53727 | Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file` | 高危 | RubyGemscss_parser | 已审查 | 2026-07-09 21:43 | 2026-07-09 21:43 |
| GHSA-7CMJ-V6X8-FRVV CVE-2026-49485 | org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint | 高危 | Mavenca.uhn.hapi.fhir:org.hl7.fhir.dstu2+7 | 已审查 | 2026-07-09 21:43 | 2026-07-09 21:43 |
| GHSA-8F95-V3JQ-CJ86 CVE-2026-53720 | pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small | 中危 | PyPIpymonocypher | 已审查 | 2026-07-09 21:42 | 2026-07-09 21:42 |
| GHSA-RQRH-8WPV-X7HH CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | 高危 | Gogithub.com/enchant97/note-mark/backend | 已审查 | 2026-07-09 21:41 | 2026-07-09 21:41 |
| GHSA-588F-FVCV-XHVF CVE-2026-50554 | Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books | 中危 | Gogithub.com/enchant97/note-mark/backend | 已审查 | 2026-07-09 21:41 | 2026-07-09 21:41 |
| GHSA-836R-79RF-4M37 CVE-2026-49477 | Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser | 高危 | PyPIsoupsieve | 已审查 | 2026-07-09 21:37 | 2026-07-09 21:37 |
| GHSA-2WC2-FM75-P42X CVE-2026-49476 | Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists | 高危 | PyPIsoupsieve | 已审查 | 2026-07-09 21:37 | 2026-07-09 21:37 |
| GHSA-52VM-MXX8-F227 | Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths | 高危 | PyPIphantom-audio | 已审查 | 2026-07-09 21:37 | 2026-07-09 21:37 |
| GHSA-Q6GH-6V2R-HJV3 | Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers | 中危 | Mavenio.micronaut:micronaut-http-client | 已审查 | 2026-07-09 21:36 | 2026-07-09 21:36 |
| GHSA-387M-935M-C4VW | Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS | 高危 | Mavenio.micronaut:micronaut-http-client | 已审查 | 2026-07-09 21:36 | 2026-07-09 21:36 |
| GHSA-C2F9-4MC8-J656 CVE-2026-48987 | pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager | 中危 | PyPIpyload-ng | 已审查 | 2026-07-09 21:35 | 2026-07-09 21:35 |
| GHSA-M5X5-28JR-GPJJ CVE-2026-48737 | pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs | 中危 | PyPIpyload-ng | 已审查 | 2026-07-09 21:35 | 2026-07-09 21:35 |
| GHSA-37H2-6P4F-MP3Q CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | 高危 | PyPIserena-agent | 已审查 | 2026-07-09 05:12 | 2026-07-09 05:12 |
| GHSA-6H3C-R723-7FX3 CVE-2026-49464 | NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak | 高危 | Mavennl.nl-portal:taak | 已审查 | 2026-07-09 05:12 | 2026-07-09 05:12 |
| GHSA-QPM9-H556-MWXM CVE-2026-49463 | NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries | 中危 | Mavennl.nl-portal:besluiten+1 | 已审查 | 2026-07-09 05:11 | 2026-07-09 05:11 |
| GHSA-43FC-V873-QW85 CVE-2026-49456 | Waku has an Open Redirect via `unstable_redirect` Helper | 低危 | npmwaku | 已审查 | 2026-07-09 04:30 | 2026-07-09 04:30 |
| GHSA-75W3-GMQX-993Q CVE-2026-49455 | Waku: Cross-Origin CSRF on RSC Server Action Dispatch | 中危 | npmwaku | 已审查 | 2026-07-09 04:27 | 2026-07-09 04:27 |