检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2GC7-W4HW-RR2M CVE-2019-19634 | class.upload.php in verot.net omits .pht from the set of dangerous file extensions | 严重 | Packagistverot/class.upload.php | 已审查 | 2020-02-28 09:10 | 2026-07-21 23:02 |
| GHSA-8RC5-HX3V-2JG7 CVE-2019-10772 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistenshrined/svg-sanitize |
| 已审查 |
| 2020-02-28 04:36 |
| 2021-08-20 03:25 |
| GHSA-P5W7-QMQ6-PMJR CVE-2019-12413 | Users able to query database metadata in Apache Superset | 中危 | PyPIapache-superset | 已审查 | 2020-02-27 03:55 | 2024-09-06 05:41 |
| GHSA-9C29-9H4M-WG5P CVE-2019-12414 | Users can view database names in Apache Superset | 中危 | PyPIapache-superset | 已审查 | 2020-02-27 03:55 | 2024-09-06 05:39 |
| GHSA-FXJM-WVJ9-9C39 CVE-2020-1932 | Information disclosure in Apache Superset | 中危 | PyPIapache-superset | 已审查 | 2020-02-27 03:54 | 2024-09-06 05:34 |
| GHSA-3M93-M4Q6-MC6V CVE-2019-14864 | Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible | 中危 | PyPIansible | 已审查 | 2020-02-27 03:54 | 2024-09-05 04:27 |
| GHSA-7553-JR98-VX47 CVE-2020-7595 | libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation | 高危 | RubyGemsnokogiri | 已审查 | 2020-02-25 03:12 | 2022-04-23 01:29 |
| GHSA-9R27-994C-4XCH | discord-html not escaping HTML code blocks when lacking a language identifier | 高危 | npmdiscord-markdown | 已审查 | 2020-02-25 01:34 | 2020-02-22 04:20 |
| GHSA-Q65M-PV3F-WR5R CVE-2020-6802 | XSS in Bleach when noscript and raw tag whitelisted | 中危 | PyPIbleach | 已审查 | 2020-02-25 01:33 | 2024-09-13 23:05 |
| GHSA-QVRV-2X7X-78X2 CVE-2019-19325 | Reflected XSS in SilverStripe | 中危 | Packagistsilverstripe/framework | 已审查 | 2020-02-25 01:33 | 2024-02-07 01:33 |
| GHSA-3MCP-9WR4-CJQF CVE-2020-5245 | Remote Code Execution (RCE) vulnerability in dropwizard-validation | 高危 | Mavenio.dropwizard:dropwizard-validation | 已审查 | 2020-02-25 01:27 | 2025-07-04 03:49 |
| GHSA-3J78-7M59-R7GV CVE-2020-5244 | Private data exposure via REST API in BuddyPress | 高危 | Packagistbuddypress/buddypress | 已审查 | 2020-02-25 01:18 | 2021-01-09 04:29 |
| GHSA-FF2W-CQ2G-WV5F CVE-2020-7238 | HTTP Request Smuggling in Netty | 高危 | Mavenio.netty:netty-handler | 已审查 | 2020-02-22 02:55 | 2021-08-20 01:32 |
| GHSA-CQQJ-4P63-RRMM CVE-2019-20444 | HTTP Request Smuggling in Netty | 严重 | Mavenio.netty:netty+2 | 已审查 | 2020-02-22 02:55 | 2025-07-02 23:50 |
| GHSA-P2V9-G2QV-P635 CVE-2019-20445 | HTTP Request Smuggling in Netty | 中危 | Mavenio.netty:netty+2 | 已审查 | 2020-02-22 02:55 | 2021-08-26 01:37 |
| GHSA-CMCX-XHR8-3W9P CVE-2020-5243 | Denial of Service in uap-core when processing crafted User-Agent strings | 中危 | npmuap-core+1 | 已审查 | 2020-02-21 07:26 | 2024-02-09 06:49 |
| GHSA-5Q88-CJFQ-G2MH CVE-2020-7597 | codecov NPM module allows remote attackers to execute arbitrary commands | 高危 | npmcodecov | 已审查 | 2020-02-20 01:29 | 2021-08-20 01:22 |
| GHSA-MXHP-79QH-MCX6 CVE-2019-10790 | TaffyDB can allow access to any data items in the DB | 高危 | npmtaffy+1 | 已审查 | 2020-02-20 00:43 | 2023-01-31 03:22 |
| GHSA-X8WJ-6M73-GFQP CVE-2020-5237 | Relative Path Traversal (CWE-23) in chunked uploads in oneup/uploader-bundle | 高危 | Packagistoneup/uploader-bundle | 已审查 | 2020-02-19 02:59 | 2021-01-09 04:30 |
| GHSA-5XF4-F2FQ-F69J CVE-2019-10773 | Yarn Improper link resolution before file access (Link Following) | 高危 | npmyarn | 已审查 | 2020-02-15 07:10 | 2023-09-09 06:40 |
| GHSA-C5R5-7PFH-6QG6 CVE-2019-10780 | BibTeX-Ruby vulnerable to OS command injection | 严重 | RubyGemsbibtex-ruby | 已审查 | 2020-02-15 07:10 | 2023-08-29 03:12 |
| GHSA-934X-72XH-5HRG CVE-2019-10777 | OS command injection in aws-lambda | 严重 | npmaws-lambda | 已审查 | 2020-02-15 07:09 | 2021-08-20 01:15 |
| GHSA-84CM-V6JP-GJMR CVE-2019-10776 | OS command injection in git-diff-apply | 严重 | npmgit-diff-apply | 已审查 | 2020-02-15 07:09 | 2021-08-20 01:14 |
| GHSA-WP7M-MRVF-599C CVE-2019-15597 | Command Injection in node-df | 严重 | npmnode-df | 已审查 | 2020-02-15 07:09 | 2021-11-01 22:12 |
| GHSA-R5FX-8R73-V86C CVE-2019-14863 | AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes | 中危 | npmangular | 已审查 | 2020-02-15 07:08 | 2025-11-21 03:30 |