检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WVPV-FFCV-R6CW CVE-2020-11005 | Internal NCryptDecrypt method could be used externally from WindowsHello library. | 中危 | NuGetHaemmerElectronics.SeppPenner.WindowsHello | 已审查 | 2020-04-15 07:09 | 2021-01-09 04:22 |
| GHSA-4GP3-P7PH-X2JR CVE-2019-10778 | OS Command Injection in devcert-sanscache |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npmdevcert-sanscache |
| 已审查 |
| 2020-04-15 07:09 |
| 2021-08-23 23:12 |
| GHSA-3944-787C-F852 CVE-2020-10203 | Persistent Cross-Site scripting in Nexus Repository Manager | 中危 | Mavenorg.sonatype.nexus:nexus-core | 已审查 | 2020-04-14 23:27 | 2021-08-23 23:11 |
| GHSA-8H56-V53H-5HHJ CVE-2020-10204 | Remote Code Execution - JavaEL Injection (low privileged accounts) in Nexus Repository Manager | 高危 | Mavenorg.sonatype.nexus:nexus-core | 已审查 | 2020-04-14 23:27 | 2021-07-29 05:49 |
| GHSA-G2F6-V5QH-H2MQ CVE-2020-10199 | Nexus Repository Manager 3 - Remote Code Execution | 高危 | Mavenorg.sonatype.nexus:nexus-extdirect | 已审查 | 2020-04-14 23:27 | 2025-10-23 01:49 |
| GHSA-8JPX-M2WH-2V34 CVE-2020-11002 | Remote Code Execution (RCE) vulnerability in dropwizard-validation | 高危 | Mavenio.dropwizard:dropwizard-validation | 已审查 | 2020-04-11 02:42 | 2021-01-09 04:22 |
| GHSA-PRFQ-F66G-43MP CVE-2020-5263 | Information disclosure through error object in auth0.js | 高危 | npmauth0-js | 已审查 | 2020-04-11 02:19 | 2021-01-09 04:23 |
| GHSA-JGPQ-G82G-6C39 CVE-2020-7638 | confinit vulnerable to prototype pollution | 中危 | npmconfinit | 已审查 | 2020-04-07 23:52 | 2021-07-29 07:16 |
| GHSA-6GP3-H3JJ-PRX4 CVE-2020-7637 | Prototype pollution in class-transformer | 中危 | npmclass-transformer | 已审查 | 2020-04-07 23:47 | 2022-04-29 01:58 |
| GHSA-6CHW-6FRG-F759 | Regular Expression Denial of Service in Acorn | 高危 | npmacorn | 已审查 | 2020-04-04 05:48 | 2021-08-23 23:10 |
| GHSA-VH95-RMGR-6W4M CVE-2020-7598 | Prototype Pollution in minimist | 中危 | npmminimist | 已审查 | 2020-04-04 05:48 | 2024-02-14 04:00 |
| GHSA-GV3V-92V6-M48J CVE-2020-7622 | Improper Neutralization of CRLF Sequences in HTTP Headers in Jooby ('HTTP Response Splitting) | 严重 | Mavenio.jooby:jooby-netty | 已审查 | 2020-04-03 23:23 | 2021-07-29 23:47 |
| GHSA-5GM3-PX64-RW72 CVE-2019-19911 | Uncontrolled Resource Consumption in Pillow | 高危 | PyPIpillow | 已审查 | 2020-04-02 00:36 | 2024-10-08 21:04 |
| GHSA-4G46-5GRC-WQ49 CVE-2019-15603 | Cross-Site Scripting in seeftl | 高危 | npmseeftl | 已审查 | 2020-04-02 00:36 | 2020-09-01 02:59 |
| GHSA-GVR4-7XGC-GX3W CVE-2019-15602 | Cross-Site Scripting in fileview | 高危 | npmfileview | 已审查 | 2020-04-02 00:36 | 2020-09-01 02:59 |
| GHSA-HJ69-C76V-86WR CVE-2020-5313 | Out-of-bounds Read in Pillow | 高危 | PyPIPillow | 已审查 | 2020-04-02 00:36 | 2024-10-08 20:57 |
| GHSA-C2H6-7GM8-CV4W CVE-2020-5497 | XSS in MITREid Connect | 中危 | Mavenorg.mitre:openid-connect-server | 已审查 | 2020-04-02 00:35 | 2023-01-25 02:07 |
| GHSA-8QXJ-F9RH-9FG2 CVE-2019-14859 | Improper Verification of Cryptographic Signature in Pure-Python ECDSA | 严重 | PyPIecdsa | 已审查 | 2020-04-02 00:35 | 2024-09-21 00:52 |
| GHSA-9Q64-MPXX-87FG | Open Redirect in ecstatic | 高危 | npmecstatic | 已审查 | 2020-04-02 00:35 | 2020-12-16 00:51 |
| GHSA-VCJJ-XF2R-MWVC CVE-2019-14862 | XSS in knockout | 中危 | npmknockout | 已审查 | 2020-04-01 23:47 | 2022-04-26 07:07 |
| GHSA-754X-4JWP-CQP6 CVE-2019-15600 | Cross-Site Scripting in http_server | 高危 | npmhttp_server | 已审查 | 2020-04-01 01:02 | 2023-09-12 05:38 |
| GHSA-J27J-4W6M-8FC4 CVE-2019-15596 | Path Traversal in statics-server | 中危 | npmstatics-server | 已审查 | 2020-04-01 01:02 | 2020-09-01 02:54 |
| GHSA-6C8F-QPHG-QJGP CVE-2019-20149 | Validation Bypass in kind-of | 高危 | npmkind-of | 已审查 | 2020-03-31 23:59 | 2021-08-23 23:03 |
| GHSA-H96W-MMRF-2H6V CVE-2020-10108 | Improper Input Validation in Twisted | 严重 | PyPITwisted | 已审查 | 2020-03-31 23:42 | 2024-11-26 02:33 |
| GHSA-P5XH-VX83-MXCJ CVE-2020-10109 | HTTP Request Smuggling in Twisted | 严重 | PyPITwisted | 已审查 | 2020-03-31 23:40 | 2024-11-26 02:33 |