检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-55F6-4PR5-C7M5 | Kahi has privilege-drop and socket/log permission issues | 高危 | Gogithub.com/kahiteam/kahi | 已审查 | 2026-07-01 02:07 | 2026-07-01 02:07 |
| GHSA-5Q4Q-834J-G8G4 CVE-2026-47198 | Paymenter has URL parameter injection that bypasses paid plan limits at checkout |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistpaymenter/paymenter |
| 已审查 |
| 2026-07-01 00:44 |
| 2026-07-01 00:44 |
| GHSA-W6CQ-9CF4-GQPG CVE-2023-46118 | RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API | 中危 | Hexrabbit_common | 已审查 | 2026-07-01 00:39 | 2026-07-01 00:39 |
| GHSA-V9GV-XP36-JGJ8 CVE-2022-31008 | RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins | 中危 | Hexrabbit_common | 已审查 | 2026-07-01 00:15 | 2026-07-01 00:15 |
| GHSA-V5PM-XWQC-G5WC CVE-2026-49451 | Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing | 高危 | NuGetMicrosoft.OpenApi | 已审查 | 2026-06-30 23:56 | 2026-07-06 20:57 |
| GHSA-Q5H6-FCF5-49G9 | Duplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences 已撤回 | 高危 | PyPInltk | 已审查 | 2026-06-30 11:37 | 2026-08-14 04:44 |
| GHSA-Q2M9-6JP9-C6MC CVE-2026-44840 | Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query | 高危 | Gogithub.com/dgraph-io/dgraph/v25 | 已审查 | 2026-06-30 06:53 | 2026-06-30 06:53 |
| GHSA-4V2W-2WQP-MC85 CVE-2026-48717 | OpenAM OAuth Authorization Bypass via PKCE Challenge | 中危 | Mavenorg.openidentityplatform.openam:openam-oauth2 | 已审查 | 2026-06-30 01:46 | 2026-06-30 01:46 |
| GHSA-F2CX-463Q-7M2C CVE-2026-47426 | OpenAM OAuth Client Impersonation via JWKS Resolver Cache | 高危 | Mavenorg.openidentityplatform.openam:openam-oauth2 | 已审查 | 2026-06-30 01:44 | 2026-06-30 01:44 |
| GHSA-69J4-QVQR-HPW3 CVE-2026-47424 | OpenAM Authenticated RCE via Groovy Sandbox Escape | 高危 | Mavenorg.openidentityplatform.openam:openam-scripting | 已审查 | 2026-06-30 01:43 | 2026-06-30 01:43 |
| GHSA-QRV3-253H-G69C | pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config | 高危 | npmpnpm | 已审查 | 2026-06-27 08:13 | 2026-06-27 08:13 |
| GHSA-72R4-9C5J-MJ57 | pnpm: `patch-remove` could delete project-selected files outside the patches directory | 高危 | npmpnpm | 已审查 | 2026-06-27 08:12 | 2026-06-27 08:12 |
| GHSA-FR4H-3CPH-29XV | pnpm: Hoisted install imports lockfile alias outside node_modules | 高危 | npmpnpm | 已审查 | 2026-06-27 08:02 | 2026-06-27 08:03 |
| GHSA-WW5P-J6CJ-6MQQ | Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-27 07:55 | 2026-06-27 07:55 |
| GHSA-V23M-CCFG-PQ9H CVE-2026-55700 | pnpm: `stage download` writes outside its destination directory via manifest name/version traversal | 高危 | npmpnpm | 已审查 | 2026-06-27 07:54 | 2026-06-27 07:54 |
| GHSA-4GXM-V5V7-FQC4 CVE-2026-55699 | pnpm: Reserved bin name deletes PNPM_HOME during global remove | 中危 | npmpnpm | 已审查 | 2026-06-27 07:46 | 2026-06-27 07:46 |
| GHSA-W466-C33R-3GJP CVE-2026-55698 | pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes | 高危 | npmpnpm | 已审查 | 2026-06-27 07:34 | 2026-06-27 07:34 |
| GHSA-HMGP-W9JM-VP95 CVE-2026-49338 | Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) | 高危 | Gogo.senan.xyz/gonic | 已审查 | 2026-06-27 07:33 | 2026-06-27 07:33 |
| GHSA-2FP4-5V5C-4448 CVE-2026-49339 | gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists | 高危 | Gogo.senan.xyz/gonic | 已审查 | 2026-06-27 07:32 | 2026-06-27 07:32 |
| GHSA-4GXV-P5G5-J7W7 CVE-2026-49340 | gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host | 高危 | Gogo.senan.xyz/gonic | 已审查 | 2026-06-27 07:21 | 2026-06-27 07:21 |
| GHSA-GJ8W-MVPF-X27X CVE-2026-55697 | pnpm: Repository-controlled configDependencies can select a pacquet native install engine | 高危 | npmpnpm | 已审查 | 2026-06-27 07:20 | 2026-08-14 00:06 |
| GHSA-5WX6-MG75-V57R CVE-2026-55487 | pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle | 高危 | npmpnpm | 已审查 | 2026-06-27 07:18 | 2026-06-27 07:18 |
| GHSA-3QHV-2RGH-X77R CVE-2026-55180 | pnpm: Repository config can expand victim environment secrets into registry requests before scripts run | 中危 | npmpnpm | 已审查 | 2026-06-27 07:12 | 2026-06-27 07:12 |
| GHSA-44CP-C3WW-9RV5 CVE-2026-53465 | ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-27 07:11 | 2026-06-27 07:11 |
| GHSA-J989-F892-2335 CVE-2026-53464 | ImageMagick: Memory Leak in wand option parser when providing invalid arguments | 中危 | NuGetMagick.NET-Q16-AnyCPU+16 | 已审查 | 2026-06-27 07:11 | 2026-06-27 07:11 |