—— |
| 未审查 |
| 2026-08-29 02:31 |
| 2026-08-29 02:31 |
| GHSA-786W-P5PM-CVGH CVE-2026-55584 | phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers | 高危 | Packagistphpsysinfo/phpsysinfo | 已审查 | 2026-08-29 02:30 | 2026-08-29 02:30 |
| GHSA-W98G-5W9P-P3RC CVE-2026-55245 | Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | 高危 | Gogithub.com/maximhq/bifrost/core | 已审查 | 2026-08-29 02:26 | 2026-08-29 02:26 |
| GHSA-298F-872V-2RCX CVE-2026-55588 | ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption | 低危 | Gooras.land/oras | 已审查 | 2026-08-29 02:19 | 2026-08-29 02:19 |
| GHSA-2GH4-JMWQ-RR8W CVE-2026-55485 | piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/. | 高危 | PyPIpiccolo-admin | 已审查 | 2026-08-29 02:14 | 2026-08-29 02:14 |
| GHSA-P6GW-4FRG-J7JW CVE-2026-55509 | WsgiDAV MySQL provider has a blind SQL injection | 高危 | PyPIWsgiDAV | 已审查 | 2026-08-29 02:12 | 2026-08-29 02:12 |
| GHSA-Q79R-R9XG-R863 CVE-2026-55425 | Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields | 中危 | Mavenorg.graylog2:graylog2-server | 已审查 | 2026-08-29 02:09 | 2026-08-29 02:09 |
| GHSA-575R-357H-FHCH CVE-2026-55516 | Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:06 | 2026-08-29 02:06 |
| GHSA-35CR-9HQQ-P2MG CVE-2026-55515 | Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:04 | 2026-08-29 02:04 |
| GHSA-W7QW-5WFV-GWX9 CVE-2026-55481 | Snipe-IT has CSS Injection via `header_color` Setting | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:04 | 2026-08-29 02:04 |
| GHSA-8FRH-VHGH-64CF CVE-2026-55479 | Snipe-IT has incorrect permission for legacy license checkin API | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:02 |
| GHSA-CRV3-J83J-F3R6 CVE-2026-55478 | Snipe-IT has missing object-level authorization in Kits API | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:04 |
| GHSA-53JC-27PC-X8R8 CVE-2026-55476 | Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:03 |
| GHSA-5WX7-XQ8J-V4QM CVE-2026-55475 | Snipe-IT's import created_by can be overwritten | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:01 |
| GHSA-C6F4-WJ38-M3G3 CVE-2026-55474 | Snipe-IT vulnerable to directory traversal in displaySig | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:03 |
| GHSA-8W8C-8MX9-52CW CVE-2026-55472 | Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:01 |
| GHSA-XR9M-GPHC-9P63 CVE-2026-55469 | Snipe-IT has a path traversal vulnerability via CSV import `image` field | 低危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:00 | 2026-08-29 02:00 |
| GHSA-JHPH-5Q74-PMFX CVE-2026-55466 | Snipe-IT vulnerable to stored XSS via inline-served attachment | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:59 | 2026-08-29 01:59 |
| GHSA-R52F-R9V5-66XR CVE-2026-55464 | Snipe-IT vulnerable to stored XSS via Markdown custom field | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:58 | 2026-08-29 01:58 |
| GHSA-FC33-6W3Q-538H CVE-2026-55462 | Snipe-IT has an authorization bypass on print inventory page | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:57 | 2026-08-29 01:57 |
| GHSA-WG2F-X2C2-C4RP CVE-2026-55461 | Snipe-IT has an Open Redirect After User Edit | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:57 | 2026-08-29 01:57 |
| GHSA-VGX7-C78R-69W9 CVE-2026-55460 | Snipe-IT has an authorization bypass on bulk editing users | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:48 | 2026-08-29 01:48 |
| GHSA-WHRX-MMGR-GPCF CVE-2026-55452 | Snipe-IT has CSV formula injection in Activity Report export | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:46 | 2026-08-29 01:46 |
| GHSA-9272-WG2R-7XMX CVE-2026-55566 | Yamcs has DOM XSS in Extension Routing | 中危 | Mavenorg.yamcs:yamcs-core | 已审查 | 2026-08-29 01:32 | 2026-08-29 01:32 |