检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G6WQ-QCWM-J5G2 CVE-2020-7663 | Regular Expression Denial of Service in websocket-extensions (RubyGem) | 高危 | RubyGemswebsocket-extensions | 已审查 | 2020-06-05 22:21 | 2023-05-17 00:17 |
| GHSA-VWQQ-5VRC-XW9H CVE-2020-9488 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Mavenorg.apache.logging.log4j:log4j+1 |
| 已审查 |
| 2020-06-05 22:15 |
| 2026-06-09 18:30 |
| GHSA-C8WH-6JW4-2H79 CVE-2020-11094 | Potential unauthorized access to stored request & session data when plugin is misconfigured in October CMS Debugbar | 中危 | Packagistrainlab/debugbar-plugin | 已审查 | 2020-06-04 07:19 | 2021-01-09 04:14 |
| GHSA-X7M2-6G99-84W5 CVE-2020-7652 | Arbitrary File Read in Snyk Broker | 中危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-08-26 05:46 |
| GHSA-4VJ3-F849-5R48 CVE-2020-7653 | Arbitrary File Read in Snyk Broker | 中危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-07-30 01:23 |
| GHSA-9XV2-548X-5H79 CVE-2020-7648 | Arbitrary File Read in Snyk Broker | 中危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-07-30 01:46 |
| GHSA-2FMP-7XWF-WVWR CVE-2020-7650 | Arbitrary File Read in Snyk Broker | 中危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-07-30 01:47 |
| GHSA-MGH5-4H95-QJ4P CVE-2020-7654 | Information Exposure in Snyk Broker | 高危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-07-30 01:51 |
| GHSA-45HW-29X7-9X95 CVE-2020-7651 | Arbitrary File Read in Snyk Broker | 中危 | npmsnyk-broker | 已审查 | 2020-06-04 06:02 | 2021-07-30 01:23 |
| GHSA-4RHM-M2FP-HX7Q CVE-2020-5299 | Potential CSV Injection vector in OctoberCMS | 中危 | Packagistoctober/backend | 已审查 | 2020-06-04 05:58 | 2021-03-05 02:26 |
| GHSA-GG6X-XX78-448C CVE-2020-5298 | Reflected XSS when importing CSV in OctoberCMS | 中危 | Packagistoctober/backend | 已审查 | 2020-06-04 05:58 | 2021-03-05 02:26 |
| GHSA-9722-RR68-RFPG CVE-2020-5297 | Upload whitelisted files to any directory in OctoberCMS | 低危 | Packagistoctober/cms | 已审查 | 2020-06-04 05:58 | 2021-03-05 02:26 |
| GHSA-JV6V-FVVX-4932 CVE-2020-5296 | Arbitrary File Deletion vulnerability in OctoberCMS | 中危 | Packagistoctober/cms | 已审查 | 2020-06-04 05:58 | 2021-03-05 02:28 |
| GHSA-R23F-C2J5-RX2F CVE-2020-5295 | Local File read vulnerability in OctoberCMS | 中危 | Packagistoctober/cms | 已审查 | 2020-06-04 05:58 | 2021-03-05 02:20 |
| GHSA-38F9-M297-6Q9G CVE-2020-4035 | DoS via malicious record IDs in WatermelonDB | 中危 | npm@nozbe/watermelondb | 已审查 | 2020-06-04 05:57 | 2021-01-09 04:15 |
| GHSA-R5JW-62XG-J433 CVE-2020-11082 | Cross-Site Scripting in Kaminari | 中危 | RubyGemskaminari | 已审查 | 2020-05-29 05:10 | 2021-09-23 21:55 |
| GHSA-WH69-WC6Q-7888 CVE-2020-11079 | Command injection in node-dns-sync | 高危 | npmdns-sync | 已审查 | 2020-05-29 02:42 | 2026-01-15 06:17 |
| GHSA-QFCV-5WHW-7PCW CVE-2020-11059 | Exposure of Sensitive Information to an Unauthorized Actor in AEgir | 严重 | npmaegir | 已审查 | 2020-05-28 05:09 | 2021-10-09 03:56 |
| GHSA-F7HX-FQXW-RVVJ CVE-2020-13625 | Insufficient output escaping of attachment names in PHPMailer | 高危 | Packagistphpmailer/phpmailer | 已审查 | 2020-05-28 00:37 | 2023-01-21 06:02 |
| GHSA-JP5V-5GX4-JMJ9 CVE-2020-8166 | Ability to forge per-form CSRF tokens in Rails | 中危 | RubyGemsactionpack | 已审查 | 2020-05-26 23:11 | 2026-05-06 06:16 |
| GHSA-M42X-37P3-FV5W CVE-2020-8162 | Circumvention of file size limits in ActiveStorage | 高危 | RubyGemsactivestorage | 已审查 | 2020-05-26 23:09 | 2023-07-06 03:19 |
| GHSA-8727-M6GJ-MC37 CVE-2020-8164 | Possible Strong Parameters Bypass in ActionPack | 高危 | RubyGemsactionpack | 已审查 | 2020-05-26 23:09 | 2023-09-26 00:55 |
| GHSA-2P68-F74V-9WC6 CVE-2020-8165 | ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore | 严重 | RubyGemsactivesupport | 已审查 | 2020-05-26 22:49 | 2025-05-10 05:34 |
| GHSA-42F2-F9VC-6365 CVE-2019-12423 | Private key leak in Apache CXF | 高危 | Mavenorg.apache.cxf:apache-cxf+1 | 已审查 | 2020-05-23 03:23 | 2021-06-16 01:26 |
| GHSA-W64W-QQPH-5GXM CVE-2020-11077 | HTTP Smuggling via Transfer-Encoding Header in Puma | 中危 | RubyGemspuma | 已审查 | 2020-05-22 22:55 | 2023-05-16 23:55 |