检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5H9J-Q6J2-253F CVE-2019-17632 | Unescaped exception messages in error responses in Jetty | 中危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2019-12-03 02:13 | 2021-06-16 01:23 |
| GHSA-QHRX-HCM6-PMRW CVE-2019-11458 | Unsafe deserialization in SmtpTransport in CakePHP |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistcakephp/cakephp |
| 已审查 |
| 2019-12-03 02:12 |
| 2025-05-30 06:52 |
| GHSA-6RMQ-X2HV-VXPP CVE-2019-6338 | Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data | 高危 | Packagistdrupal/drupal | 已审查 | 2019-12-03 02:11 | 2024-02-05 23:41 |
| GHSA-X92H-WMG2-6HP7 CVE-2019-10913 | Invalid HTTP method overrides allow possible XSS or other attacks in Symfony | 严重 | Packagistsymfony/http-foundation+1 | 已审查 | 2019-12-03 02:10 | 2021-08-19 23:18 |
| GHSA-4VPC-5JX4-CFQG CVE-2019-18886 | User enumeration leak using switch user functionality in Symfony | 中危 | Packagistsymfony/security-http+1 | 已审查 | 2019-12-03 02:09 | 2021-07-28 23:49 |
| GHSA-XHH6-956Q-4Q69 CVE-2019-18888 | Argument injection in a MimeTypeGuesser in Symfony | 高危 | Packagistsymfony/http-foundation+2 | 已审查 | 2019-12-03 02:08 | 2021-07-29 00:28 |
| GHSA-79GR-58R3-PWM3 CVE-2019-18889 | Symfony Unsafe Cache Serialization Could Enable RCE | 严重 | Packagistsymfony/cache+1 | 已审查 | 2019-12-03 02:07 | 2024-02-01 23:48 |
| GHSA-CMCH-296J-WFVW CVE-2019-10767 | Arbitrary File Write in iobroker.js-controller | 高危 | npmiobroker.js-controller | 已审查 | 2019-12-03 02:06 | 2021-08-19 23:11 |
| GHSA-FPFF-384J-VXQ7 CVE-2019-10763 | Data leakage via SQL Injection in Pimcore | 中危 | Packagistpimcore/pimcore | 已审查 | 2019-12-03 02:05 | 2021-08-19 23:10 |
| GHSA-5PM8-492C-92P5 CVE-2019-18841 | Prototype Pollution in chartkick | 高危 | npmchartkick | 已审查 | 2019-12-03 02:04 | 2023-01-27 04:23 |
| GHSA-7XXV-WPXJ-MX5V CVE-2019-19275 | typed-ast Out-of-bounds Read | 高危 | PyPItyped-ast | 已审查 | 2019-12-03 02:03 | 2024-11-19 06:15 |
| GHSA-M3JW-62M7-JJCM CVE-2019-19274 | typed-ast Out-of-bounds Read | 高危 | PyPItyped-ast | 已审查 | 2019-12-03 02:02 | 2024-09-10 05:35 |
| GHSA-89PX-WW3J-G2MM CVE-2019-16766 | 2FA bypass in Wagtail through new device path | 中危 | PyPIwagtail-2fa | 已审查 | 2019-11-30 01:05 | 2024-11-19 23:48 |
| GHSA-M52X-29PQ-W3VV CVE-2019-16763 | Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript | 中危 | npmpannellum | 已审查 | 2019-11-23 02:18 | 2022-08-03 21:00 |
| GHSA-9XR8-8HMC-389F | Cross-Site Scripting in vant | 高危 | npmvant | 已审查 | 2019-11-22 21:45 | 2021-08-19 06:47 |
| GHSA-Q3P4-GW7R-WQJC CVE-2019-12417 | Apache Airflow vulnerable to XSS and local file disclosure | 中危 | PyPIairflow | 已审查 | 2019-11-22 21:45 | 2024-09-12 01:09 |
| GHSA-68WG-QV6R-J4VP CVE-2019-10766 | SQL Injection in usmanhalalit/pixie | 严重 | Packagistusmanhalalit/pixie | 已审查 | 2019-11-21 01:44 | 2021-08-19 06:44 |
| GHSA-89MQ-4X47-5V83 CVE-2019-10768 | angular Prototype Pollution vulnerability | 高危 | npmangular | 已审查 | 2019-11-20 23:29 | 2025-11-21 03:29 |
| GHSA-VVWV-H69M-WG6F CVE-2019-12331 | XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue | 高危 | Packagistphpoffice/phpexcel+1 | 已审查 | 2019-11-20 09:39 | 2025-03-07 02:02 |
| GHSA-XCRG-29H7-H4CJ CVE-2018-19277 | XXE in PHPSpreadsheet due to encoding issue | 高危 | Packagistphpoffice/phpexcel+1 | 已审查 | 2019-11-20 09:38 | 2025-03-07 02:08 |
| GHSA-HX83-RPQF-M267 CVE-2018-11768 | user/group information can be corrupted across storing in fsimage and reading back from fsimage | 高危 | Mavenorg.apache.hadoop:hadoop-main | 已审查 | 2019-11-20 09:38 | 2021-08-19 06:42 |
| GHSA-VRCF-G539-X6H3 CVE-2019-17206 | Uncontrolled deserialization of a pickled object in rediswrapper allows attackers to execute arbitrary scripts | 严重 | PyPIrediswrapper | 已审查 | 2019-11-20 09:37 | 2024-10-27 02:41 |
| GHSA-9GGP-4JPR-7PPJ | Duplicate Advisory: Possible remote code execution via a remote procedure call 已撤回 | 高危 | PyPIrpyc | 已审查 | 2019-11-20 09:35 | 2024-10-27 06:38 |
| GHSA-MR6R-82X4-F4JJ CVE-2019-10764 | Timing attacks might allow practical recovery of the long-term private key | 高危 | Packagistsimplito/elliptic-php | 已审查 | 2019-11-20 09:34 | 2021-08-19 06:40 |
| GHSA-8VH8-VC28-M2HF CVE-2019-10212 | Potential to access user credentials from the log files when debug logging enabled | 严重 | Mavenio.undertow:undertow-core | 已审查 | 2019-11-20 09:33 | 2022-02-12 05:12 |