检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HGPF-8634-G44C CVE-2026-55873 | SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets | 中危 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-08-29 06:16 | 2026-08-29 06:16 |
| GHSA-J769-9GV9-65GR CVE-2026-55867 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.graylog2:graylog2-server |
| 已审查 |
| 2026-08-29 06:15 |
| 2026-08-29 06:15 |
| GHSA-GQR6-R77P-C2PJ CVE-2026-55841 | Fortigate syslog message parser can be exploited to modify or delete fields from the original message | 高危 | Mavenorg.graylog2:graylog2-server | 已审查 | 2026-08-29 06:13 | 2026-08-29 06:13 |
| GHSA-MRPP-V6PG-P54X CVE-2026-55764 | klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-08-29 06:08 | 2026-08-29 06:08 |
| GHSA-42R5-VHPQ-M858 CVE-2026-55854 | MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials | 中危 | npmmariadb | 已审查 | 2026-08-29 06:04 | 2026-08-29 06:04 |
| GHSA-P378-JP5R-GPGW CVE-2026-55678 | arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset | 中危 | Gogithub.com/basekick-labs/arc | 已审查 | 2026-08-29 04:32 | 2026-08-29 04:32 |
| GHSA-X626-FCWX-F5PC CVE-2026-55761 | Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances | 高危 | Gogithub.com/portainer/portainer | 已审查 | 2026-08-29 04:28 | 2026-08-29 04:28 |
| GHSA-V358-WF77-39XV CVE-2026-55763 | klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits | 高危 | Gogithub.com/klever-io/klever-go | 已审查 | 2026-08-29 04:27 | 2026-08-29 04:27 |
| GHSA-XRJC-C68J-HP7W CVE-2026-55891 | PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI | 低危 | Packagistprivatebin/privatebin | 已审查 | 2026-08-29 04:25 | 2026-08-29 04:25 |
| GHSA-F2XF-7X3G-4272 CVE-2026-55696 | PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction | 中危 | Packagistprivatebin/privatebin | 已审查 | 2026-08-29 04:22 | 2026-08-29 04:23 |
| GHSA-73P9-6HRP-8QHR | AIIR verification and policy gates could report success without enforcing the control (fail-open) | 中危 | PyPIaiir | 已审查 | 2026-08-29 03:20 | 2026-08-29 03:20 |
| GHSA-HR6J-W4MW-G9MJ CVE-2026-55484 | alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server | 高危 | Gogithub.com/guno1928/alos-http | 已审查 | 2026-08-29 03:19 | 2026-08-29 03:19 |
| GHSA-9X44-4GXF-8C25 CVE-2026-55634 | Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name | 严重 | Packagistpimcore/pimcore | 已审查 | 2026-08-29 03:17 | 2026-08-29 03:17 |
| GHSA-W23P-WRP7-CH38 CVE-2026-55220 | Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502) | 严重 | Packagistpimcore/pimcore | 已审查 | 2026-08-29 03:13 | 2026-08-29 03:13 |
| GHSA-F97C-PH8J-8VFF CVE-2026-55212 | Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation | 高危 | Packagistpimcore/studio-backend-bundle | 已审查 | 2026-08-29 03:05 | 2026-08-29 03:05 |
| GHSA-79CW-HFCC-7MW9 CVE-2026-55208 | Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes | 高危 | Packagistpimcore/studio-backend-bundle | 已审查 | 2026-08-29 03:04 | 2026-08-29 03:04 |
| GHSA-H854-C3M3-MH5V CVE-2026-55207 | Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass | 高危 | Packagistpimcore/studio-backend-bundle | 已审查 | 2026-08-29 03:04 | 2026-08-29 03:04 |
| GHSA-CQHC-2H57-WPXF CVE-2026-55215 | MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` | 高危 | npmmariadb | 已审查 | 2026-08-29 03:03 | 2026-08-29 03:03 |
| GHSA-R82H-MQW3-FC56 CVE-2026-55247 | plone.app.event vulnerable to denial of service via iCalendar import | 严重 | PyPIplone.app.event | 已审查 | 2026-08-29 02:59 | 2026-08-29 02:59 |
| GHSA-C9F5-J9C3-MHRG CVE-2026-55622 | Incus has a project restriction bypass in instance copy across projects | 高危 | Gogithub.com/lxc/incus/v7/cmd/incusd | 已审查 | 2026-08-29 02:57 | 2026-08-29 02:57 |
| GHSA-64F3-V33M-W89F CVE-2026-55621 | Incus has a project restriction bypass for custom volume copy across projects | 高危 | Gogithub.com/lxc/incus+2 | 已审查 | 2026-08-29 02:52 | 2026-08-29 02:52 |
| GHSA-2Q2Q-JR9G-V9RF CVE-2026-55228 | Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project | 高危 | PyPIWeblate | 已审查 | 2026-08-29 02:47 | 2026-08-29 02:47 |
| GHSA-2P9G-X3CV-5HH4 CVE-2026-55227 | Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups | 中危 | PyPIweblate | 已审查 | 2026-08-29 02:46 | 2026-08-29 02:46 |
| GHSA-WJMF-P669-5M5P CVE-2026-55520 | Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching | 高危 | PyPIProtego | 已审查 | 2026-08-29 02:43 | 2026-08-29 02:43 |
| GHSA-X5G3-W747-2H8Q CVE-2026-55248 | plone.app.portlets vulnerable to denial of service via RSS feed portlet | 严重 | PyPIplone.app.portlets | 已审查 | 2026-08-29 02:41 | 2026-08-29 02:41 |