检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q9CP-MC96-M4W2 CVE-2020-26229 | XML External Entity in Dashboard Widget | 低危 | Packagisttypo3/cms+1 | 已审查 | 2020-11-24 05:18 | 2024-02-05 19:16 |
| GHSA-954J-F27R-CJ52 CVE-2020-26228 | Cleartext storage of session identifier |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagisttypo3/cms+1 |
| 已审查 |
| 2020-11-24 05:18 |
| 2024-02-05 19:15 |
| GHSA-R89V-CGV7-3JHX CVE-2020-26231 | Bypass of fix for CVE-2020-15247, Twig sandbox escape | 低危 | Packagistoctober/cms | 已审查 | 2020-11-24 04:54 | 2021-03-05 02:24 |
| GHSA-94VP-RMQV-5875 CVE-2020-15247 | Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled. | 中危 | Packagistoctober/cms | 已审查 | 2020-11-24 03:48 | 2021-11-19 21:42 |
| GHSA-XWJR-6FJ7-FC6H CVE-2020-15246 | Local File Inclusion by unauthenticated users | 高危 | Packagistoctober/cms | 已审查 | 2020-11-24 03:48 | 2021-11-19 21:46 |
| GHSA-FX3V-553X-3C4Q CVE-2020-15249 | Stored XSS by authenticated backend user with access to upload files | 低危 | Packagistoctober/backend | 已审查 | 2020-11-24 03:47 | 2021-03-05 02:24 |
| GHSA-RFJC-XRMF-5VVW CVE-2020-15248 | Privilege escalation by backend users assigned to the default "Publisher" system role | 低危 | Packagistoctober/backend | 已审查 | 2020-11-24 03:47 | 2021-11-19 21:40 |
| GHSA-R2J6-P67H-Q639 CVE-2020-26226 | Secret disclosure when containing characters that become URI encoded | 高危 | npmsemantic-release | 已审查 | 2020-11-19 05:19 | 2021-01-08 06:41 |
| GHSA-C7VM-F5P4-8FQH CVE-2020-26215 | Open redirect in Jupyter Notebook | 低危 | PyPInotebook | 已审查 | 2020-11-19 05:06 | 2024-09-26 01:58 |
| GHSA-HPJM-3WW5-6CPF CVE-2020-26216 | Cross-Site Scripting through Fluid view helper arguments | 高危 | Packagisttypo3fluid/fluid | 已审查 | 2020-11-19 05:06 | 2024-02-08 02:52 |
| GHSA-58W4-W77W-QV3W CVE-2020-26225 | Reflected XSS with parameters in PostComment | 中危 | Packagistprestashop/productcomments | 已审查 | 2020-11-17 05:23 | 2021-01-08 06:42 |
| GHSA-MW36-7C6C-Q4Q2 CVE-2020-26217 | XStream can be used for Remote Code Execution | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2020-11-17 04:07 | 2025-09-03 23:04 |
| GHSA-HRFH-FP4X-CRRQ | Persistent XSS in newsletter module in Shopware | 低危 | Packagistshopware/shopware | 已审查 | 2020-11-14 02:26 | 2020-11-14 02:00 |
| GHSA-28FW-88HQ-6JMM | Persistent XSS in shopping worlds | 低危 | Packagistshopware/shopware | 已审查 | 2020-11-14 02:26 | 2020-11-14 02:25 |
| GHSA-Q76J-58CX-WP5V | Vulnerability in RPKI manifest validation | 高危 | Mavennet.ripe.rpki:rpki-validator-3 | 已审查 | 2020-11-14 01:28 | 2020-11-14 01:28 |
| GHSA-XWHF-G6J5-J5GC CVE-2020-15266 | Float cast overflow undefined behavior | 中危 | PyPItensorflow+2 | 已审查 | 2020-11-14 01:18 | 2024-10-28 22:46 |
| GHSA-M2JR-HMC3-QMPR CVE-2020-26223 | Authorization bypass in Spree | 高危 | RubyGemsspree_api | 已审查 | 2020-11-14 01:18 | 2023-05-17 00:19 |
| GHSA-RRFP-J2MP-HQ9C CVE-2020-15265 | Segfault in `tf.quantization.quantize_and_dequantize` | 高危 | PyPItensorflow+2 | 已审查 | 2020-11-14 01:13 | 2024-10-31 05:22 |
| GHSA-23F7-99JX-M54R CVE-2020-26222 | Remote code execution in dependabot-core branch names when cloning | 高危 | RubyGemsdependabot-common+1 | 已审查 | 2020-11-13 23:47 | 2023-05-17 00:04 |
| GHSA-6GV9-7Q4G-PMVM | Persistent XSS in customer module in Shopware | 低危 | Packagistshopware/shopware | 已审查 | 2020-11-13 23:47 | 2020-11-13 09:17 |
| GHSA-M9HW-7XFV-WQG7 | Prototype Pollution in json-logic-js | 高危 | npmjson-logic-js | 已审查 | 2020-11-13 03:36 | 2020-11-13 03:35 |
| GHSA-8JQ6-W5CG-WM45 | Exploitable inventory component chaining in PocketMine-MP | 高危 | Packagistpocketmine/pocketmine-mp | 已审查 | 2020-11-12 05:38 | 2020-11-12 05:38 |
| GHSA-52Q8-877J-GGHQ CVE-2020-25074 | MoinMoin vulnerable to remote code execution via cache action | 高危 | PyPImoin | 已审查 | 2020-11-11 23:54 | 2024-10-07 22:54 |
| GHSA-4Q96-6XHQ-FF43 CVE-2020-15275 | malicious SVG attachment causing stored XSS vulnerability | 中危 | PyPImoin | 已审查 | 2020-11-11 23:54 | 2024-10-07 23:01 |
| GHSA-JGRH-5M3H-9C5F CVE-2020-7764 | Web Cache Poisoning in find-my-way | 中危 | npmfind-my-way | 已审查 | 2020-11-10 06:17 | 2020-11-11 04:19 |