检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JQVF-J3WW-R8C7 CVE-2026-55673 | PowSyBl Core has Command Injection in LocalCommandExecutor-s | 高危 | Mavencom.powsybl:powsybl-computation-local | 已审查 | 2026-08-29 02:37 | 2026-08-29 02:37 |
| GHSA-P68J-Q7HF-3QCP CVE-2026-55175 | Spinnaker: Improper yaml processing on kustomize bake operations |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Mavenio.spinnaker.rosco:rosco-manifests |
| 已审查 |
| 2026-08-29 02:35 |
| 2026-08-29 02:35 |
| GHSA-F9QC-QG88-7PQ5 CVE-2026-55407 | Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation | 中危 | crates.iobuffa | 已审查 | 2026-08-29 02:34 | 2026-08-29 02:34 |
| GHSA-9PWQ-GCRX-WGHH CVE-2026-55406 | Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref | 中危 | crates.iobuffa | 已审查 | 2026-08-29 02:33 | 2026-08-29 02:33 |
| GHSA-86M2-FCXQ-5Q7C CVE-2026-55641 | 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF | 高危 | npm9router | 已审查 | 2026-08-29 02:33 | 2026-08-29 02:33 |
| GHSA-8GMQ-J984-VP4R CVE-2026-55638 | 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass | 高危 | npm9router | 已审查 | 2026-08-29 02:32 | 2026-08-29 02:32 |
| GHSA-786W-P5PM-CVGH CVE-2026-55584 | phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers | 高危 | Packagistphpsysinfo/phpsysinfo | 已审查 | 2026-08-29 02:30 | 2026-08-29 02:30 |
| GHSA-W98G-5W9P-P3RC CVE-2026-55245 | Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | 高危 | Gogithub.com/maximhq/bifrost/core | 已审查 | 2026-08-29 02:26 | 2026-08-29 02:26 |
| GHSA-298F-872V-2RCX CVE-2026-55588 | ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption | 低危 | Gooras.land/oras | 已审查 | 2026-08-29 02:19 | 2026-08-29 02:19 |
| GHSA-2GH4-JMWQ-RR8W CVE-2026-55485 | piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/. | 高危 | PyPIpiccolo-admin | 已审查 | 2026-08-29 02:14 | 2026-08-29 02:14 |
| GHSA-P6GW-4FRG-J7JW CVE-2026-55509 | WsgiDAV MySQL provider has a blind SQL injection | 高危 | PyPIWsgiDAV | 已审查 | 2026-08-29 02:12 | 2026-08-29 02:12 |
| GHSA-Q79R-R9XG-R863 CVE-2026-55425 | Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields | 中危 | Mavenorg.graylog2:graylog2-server | 已审查 | 2026-08-29 02:09 | 2026-08-29 02:09 |
| GHSA-575R-357H-FHCH CVE-2026-55516 | Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:06 | 2026-08-29 02:06 |
| GHSA-35CR-9HQQ-P2MG CVE-2026-55515 | Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:04 | 2026-08-29 02:04 |
| GHSA-W7QW-5WFV-GWX9 CVE-2026-55481 | Snipe-IT has CSS Injection via `header_color` Setting | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:04 | 2026-08-29 02:04 |
| GHSA-8FRH-VHGH-64CF CVE-2026-55479 | Snipe-IT has incorrect permission for legacy license checkin API | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:02 |
| GHSA-CRV3-J83J-F3R6 CVE-2026-55478 | Snipe-IT has missing object-level authorization in Kits API | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:04 |
| GHSA-53JC-27PC-X8R8 CVE-2026-55476 | Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:02 | 2026-08-29 02:03 |
| GHSA-5WX7-XQ8J-V4QM CVE-2026-55475 | Snipe-IT's import created_by can be overwritten | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:01 |
| GHSA-C6F4-WJ38-M3G3 CVE-2026-55474 | Snipe-IT vulnerable to directory traversal in displaySig | 高危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:03 |
| GHSA-8W8C-8MX9-52CW CVE-2026-55472 | Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:01 | 2026-08-29 02:01 |
| GHSA-XR9M-GPHC-9P63 CVE-2026-55469 | Snipe-IT has a path traversal vulnerability via CSV import `image` field | 低危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 02:00 | 2026-08-29 02:00 |
| GHSA-JHPH-5Q74-PMFX CVE-2026-55466 | Snipe-IT vulnerable to stored XSS via inline-served attachment | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:59 | 2026-08-29 01:59 |
| GHSA-R52F-R9V5-66XR CVE-2026-55464 | Snipe-IT vulnerable to stored XSS via Markdown custom field | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:58 | 2026-08-29 01:58 |
| GHSA-FC33-6W3Q-538H CVE-2026-55462 | Snipe-IT has an authorization bypass on print inventory page | 中危 | Packagistsnipe/snipe-it | 已审查 | 2026-08-29 01:57 | 2026-08-29 01:57 |