检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7XCV-WVR7-4H6P | Malicious npm package: an0n-chat-lib | 严重 | npman0n-chat-lib | 已审查 | 2021-01-30 02:12 | 2021-01-30 02:11 |
| GHSA-QV2G-99X4-45X6 | Malicious npm package: discord-fix |
当前筛选结果 35,190 条 · 时间按北京时间显示
npmdiscord-fix |
| 已审查 |
| 2021-01-30 02:12 |
| 2021-01-30 02:11 |
| GHSA-W8FH-PVQ2-X8C4 | Malicious npm package: sonatype | 严重 | npmsonatype | 已审查 | 2021-01-30 02:11 | 2021-01-30 02:10 |
| GHSA-HVF8-H2QH-37M9 CVE-2020-26272 | IPC messages delivered to the wrong frame in Electron | 中危 | npmelectron | 已审查 | 2021-01-29 03:11 | 2025-05-27 23:20 |
| GHSA-5P3X-R448-PC62 CVE-2021-21239 | Improper Verification of Cryptographic Signature in PySAML2 | 中危 | PyPIpysaml2 | 已审查 | 2021-01-21 22:12 | 2024-10-14 23:41 |
| GHSA-F4G9-H89H-JGV9 CVE-2021-21238 | SAML XML Signature wrapping in PySAML2 | 中危 | PyPIpysaml2 | 已审查 | 2021-01-21 22:12 | 2024-10-14 23:50 |
| GHSA-5V44-7647-XFW9 CVE-2020-26248 | Blind SQL injection in PrestaShop productcomments module | 低危 | Packagistprestashop/productcomments | 已审查 | 2021-01-21 05:33 | 2022-01-08 00:07 |
| GHSA-49WP-QQ6X-G2RF CVE-2020-28482 | Cross-site Request Forgery in fastify-csrf | 高危 | npmfastify-csrf | 已审查 | 2021-01-21 05:30 | 2022-06-30 05:54 |
| GHSA-9QMH-276G-X5PJ CVE-2020-28477 | Prototype Pollution in immer | 高危 | npmimmer | 已审查 | 2021-01-21 05:27 | 2024-04-26 06:17 |
| GHSA-FXWF-4RQH-V8G3 CVE-2020-28481 | CORS misconfiguration in socket.io | 中危 | npmsocket.io | 已审查 | 2021-01-21 05:22 | 2023-09-12 06:46 |
| GHSA-6G8V-HPGW-H2V7 CVE-2020-28478 | Prototype pollution in gsap | 高危 | npmgsap | 已审查 | 2021-01-21 05:21 | 2023-09-13 04:56 |
| GHSA-QWP9-52H8-XGG8 CVE-2020-28480 | Prototype pollution in JointJS | 高危 | npmjointjs | 已审查 | 2021-01-21 05:21 | 2021-01-20 13:24 |
| GHSA-5949-RW7G-WX7W CVE-2021-20190 | Deserialization of untrusted data in jackson-databind | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2021-01-21 05:20 | 2024-03-15 08:16 |
| GHSA-29V9-2FPX-J5G9 CVE-2018-8092 | CSV Injection vulnerability with exported contact lists in Mautic | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2021-01-20 05:13 |
| GHSA-9HX7-RG7W-XM79 CVE-2018-11200 | XSS vulnerability in company name field in Mautic | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2021-01-20 05:13 |
| GHSA-QJHR-C23F-W76Q CVE-2017-1000488 | Inline JS XSS vulnerability in Mautic | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2021-01-20 05:14 |
| GHSA-VFXJ-QG93-7WWC CVE-2018-10189 | Mautic Sessions could be hijacked due to tracking contacts by an auto-incremented ID | 高危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2023-09-11 23:06 |
| GHSA-6X98-FX9J-7C78 CVE-2017-1000489 | Disabled users able to log in with third party SSO plugin | 高危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2023-09-11 21:39 |
| GHSA-5W74-JX7M-X6HV CVE-2018-8071 | XSS vulnerability in theme config file in Mautic | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2023-09-11 21:42 |
| GHSA-XCF7-CJ8Q-PCJM CVE-2018-11198 | XSS vulnerability in Author URL of themes in Mautic | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 05:16 | 2023-09-11 21:41 |
| GHSA-QPGW-2C72-4C89 CVE-2017-1000490 | Mautic users able to download any files from server using filemanager | 中危 | Packagistmautic/core | 已审查 | 2021-01-20 04:50 | 2023-09-11 21:40 |
| GHSA-39WJ-J3JC-858M CVE-2020-35124 | XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic | 严重 | Packagistmautic/core | 已审查 | 2021-01-20 04:43 | 2021-01-20 04:43 |
| GHSA-3P32-J457-PG5X CVE-2021-21263 | Query Binding Exploitation | 高危 | Packagistilluminate/database+1 | 已审查 | 2021-01-20 03:36 | 2021-03-30 01:41 |
| GHSA-523C-XH4G-MH5M CVE-2017-12626 | Denial of Service in Apache POI | 高危 | Mavenorg.apache.poi:poi | 已审查 | 2021-01-15 03:18 | 2026-06-09 18:20 |
| GHSA-WJX2-7HQQ-8H7M CVE-2020-36190 | rails_admin ruby gem XSS vulnerability | 中危 | RubyGemsrails_admin | 已审查 | 2021-01-15 03:17 | 2023-07-04 05:56 |