检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J977-G5VJ-J27G CVE-2020-7750 | Cross-Site Scripting in scratch-svg-renderer | 高危 | npmscratch-svg-renderer | 已审查 | 2020-11-09 22:21 | 2021-01-08 06:49 |
| GHSA-6H7F-QWQM-35PP CVE-2020-7763 | Arbitrary File Read in phantom-html-to-pdf |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmphantom-html-to-pdf |
| 已审查 |
| 2020-11-07 02:06 |
| 2023-09-08 06:36 |
| GHSA-5HMM-X8Q8-W5JH CVE-2020-26214 | LDAP authentication bypass with empty password | 严重 | PyPIalerta-server | 已审查 | 2020-11-07 01:35 | 2024-09-05 03:53 |
| GHSA-WPWW-4JF4-4HX8 CVE-2020-15273 | Edit feed settings and others, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0 | 低危 | Packagistbaserproject/basercms | 已审查 | 2020-11-05 05:08 | 2021-01-08 06:49 |
| GHSA-P694-23Q3-RVRC CVE-2017-15708 | Remote Code Execution in Apache Synapse | 严重 | Mavenorg.apache.synapse:synapse-core | 已审查 | 2020-11-05 02:23 | 2022-03-19 04:16 |
| GHSA-G3WG-6MCF-8JJ6 CVE-2020-27216 | Local Temp Directory Hijacking Vulnerability | 高危 | Mavenorg.eclipse.jetty:jetty-webapp+1 | 已审查 | 2020-11-05 01:50 | 2023-11-28 07:07 |
| GHSA-58R4-H6V8-JCVM CVE-2020-15240 | Regression in JWT Signature Validation | 高危 | RubyGemsomniauth-auth0 | 已审查 | 2020-11-03 10:31 | 2023-05-17 00:04 |
| GHSA-FW5Q-J9P4-3VXG CVE-2020-15276 | Blog comment posting, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0 | 低危 | Packagistbaserproject/basercms | 已审查 | 2020-10-31 03:10 | 2021-01-08 06:49 |
| GHSA-JRGF-VFW2-HJ26 CVE-2020-15244 | RCE via PHP Object injection via SOAP Requests | 高危 | Packagistopenmage/magento-lts | 已审查 | 2020-10-31 01:06 | 2021-11-19 21:46 |
| GHSA-6FMV-Q269-55CW CVE-2020-15277 | Edit template, Remote Code Execution (RCE) Vulnerability in Latest Release 4.4.0 | 高危 | Packagistbaserproject/basercms | 已审查 | 2020-10-31 01:05 | 2021-01-09 05:18 |
| GHSA-QVP5-MM7V-4F36 CVE-2020-27666 | Cross-site Scripting in Strapi | 中危 | npmstrapi-plugin-content-manager | 已审查 | 2020-10-30 03:40 | 2023-09-14 06:53 |
| GHSA-4P55-XJ37-FX7G CVE-2020-27665 | Improper Authorization in Strapi | 高危 | npmstrapi-plugin-content-type-builder | 已审查 | 2020-10-30 02:29 | 2023-09-14 03:30 |
| GHSA-2XWP-M7MQ-7Q3R | CLI does not correctly implement strict mode | 低危 | PyPIaws-encryption-sdk-cli | 已审查 | 2020-10-29 01:05 | 2020-10-29 01:04 |
| GHSA-FJ59-F6C3-3VW4 CVE-2020-26300 | Command Injection in systeminformation | 中危 | npmsysteminformation | 已审查 | 2020-10-28 04:40 | 2021-09-10 22:54 |
| GHSA-C27R-X354-4M68 | xml-crypto's HMAC-SHA1 signatures can bypass validation via key confusion | 高危 | npmxml-crypto | 已审查 | 2020-10-28 04:39 | 2022-08-03 04:03 |
| GHSA-HGGM-JPG3-V476 CVE-2020-25659 | RSA decryption vulnerable to Bleichenbacher timing vulnerability | 高危 | PyPIcryptography | 已审查 | 2020-10-28 04:33 | 2024-11-19 00:26 |
| GHSA-MP9M-G7QJ-6VQR CVE-2020-15278 | Unauthorized privilege escalation in Mod module | 中危 | PyPIRed-DiscordBot | 已审查 | 2020-10-28 04:30 | 2024-10-26 05:47 |
| GHSA-94XH-2FMC-XF5J CVE-2020-7752 | systeminformation command injection vulnerability | 高危 | npmsysteminformation | 已审查 | 2020-10-28 04:30 | 2023-09-07 07:53 |
| GHSA-PV36-H7JH-QM62 CVE-2020-15999 | Heap buffer overflow in CefSharp | 中危 | NuGetCefSharp.Common+3 | 已审查 | 2020-10-28 03:47 | 2025-02-03 23:31 |
| GHSA-R82C-J4MQ-5XFW | Update bitlyshortener to >=0.5.0 to prevent generating some invalid short URLs | 高危 | PyPIbitlyshortener | 已审查 | 2020-10-28 03:19 | 2020-10-28 03:19 |
| GHSA-2XM2-XJ2Q-QGPJ CVE-2020-15270 | receiving subscription objects with deleted session | 中危 | npmparse-server | 已审查 | 2020-10-28 03:15 | 2021-10-07 06:02 |
| GHSA-C84H-W6CR-5V8Q CVE-2020-15271 | Markdown-supplied Shell Command Execution | 严重 | PyPIlookatme | 已审查 | 2020-10-28 01:59 | 2024-10-01 04:15 |
| GHSA-939M-4XPW-V34V CVE-2020-26943 | Arbitrary Code Execution in blazar-dashboard | 中危 | PyPIblazar-dashboard | 已审查 | 2020-10-28 01:55 | 2024-09-07 00:25 |
| GHSA-F8CM-364F-Q9QH CVE-2020-15269 | Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls | 高危 | RubyGemsspree | 已审查 | 2020-10-21 04:03 | 2021-11-19 21:51 |
| GHSA-H385-52J6-9984 CVE-2020-7670 | Withdrawn: HTTP Request Smuggling in Agoo 已撤回 | 中危 | RubyGemsagoo | 已审查 | 2020-10-21 03:15 | 2021-01-14 03:25 |