检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WJX2-7HQQ-8H7M CVE-2020-36190 | rails_admin ruby gem XSS vulnerability | 中危 | RubyGemsrails_admin | 已审查 | 2021-01-15 03:17 | 2023-07-04 05:56 |
| GHSA-2CCX-2GF3-8XVV CVE-2020-26253 | Kirby .dev domains and some reverse proxy setups were treated as local |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Packagistgetkirby/cms+1 |
| 已审查 |
| 2021-01-15 03:15 |
| 2022-07-21 01:00 |
| GHSA-V5RV-HPXG-8X49 CVE-2020-28042 | Signature validation bypass in ServiceStack | 中危 | NuGetServiceStack | 已审查 | 2021-01-14 03:13 | 2021-01-14 03:12 |
| GHSA-7JH9-6CPF-H4M7 CVE-2020-7741 | XSS in hello.js | 严重 | npmhellojs | 已审查 | 2021-01-14 03:07 | 2023-09-13 02:13 |
| GHSA-WW4J-C2RQ-47Q8 CVE-2020-7784 | Command injection in ts-process-promises | 严重 | npmts-process-promises | 已审查 | 2021-01-14 02:22 | 2023-09-09 04:18 |
| GHSA-487W-PQCM-63HQ CVE-2020-7794 | Command injection in buns | 严重 | npmbuns | 已审查 | 2021-01-14 02:22 | 2023-09-09 06:44 |
| GHSA-JXWX-85VP-GVWM CVE-2021-21252 | Regular Expression Denial of Service in jquery-validation | 高危 | npmjquery-validation+1 | 已审查 | 2021-01-14 02:21 | 2023-09-01 02:34 |
| GHSA-HH7M-RX4F-4VPV CVE-2021-21241 | CSRF can expose users authentication token | 高危 | PyPIFlask-Security-Too | 已审查 | 2021-01-12 04:38 | 2024-09-21 01:48 |
| GHSA-Q3WR-QW3G-3P4H CVE-2020-26298 | Injection/XSS in Redcarpet | 中危 | RubyGemsredcarpet | 已审查 | 2021-01-12 03:06 | 2022-10-08 04:41 |
| GHSA-PGWW-XF46-H92R CVE-2020-27783 | lxml vulnerable to Cross-site Scripting | 中危 | PyPIlxml | 已审查 | 2021-01-08 05:54 | 2025-12-20 13:10 |
| GHSA-395W-QHQR-9FR6 CVE-2020-17519 | Path Traversal in Apache Flink | 高危 | Mavenorg.apache.flink:flink-runtime_2.11+1 | 已审查 | 2021-01-07 04:01 | 2025-10-23 01:58 |
| GHSA-W7JX-J77M-WP65 CVE-2024-21911 | Cross-site scripting vulnerability in TinyMCE | 中危 | npmtinymce+2 | 已审查 | 2021-01-07 03:27 | 2024-01-04 06:31 |
| GHSA-H96F-FC7C-9R55 | Regex denial of service vulnerability in codesample plugin | 低危 | npmtinymce | 已审查 | 2021-01-07 03:25 | 2021-01-07 03:25 |
| GHSA-HQ37-853P-G5CF CVE-2021-21236 | Regular Expression Denial of Service in CairoSVG | 高危 | PyPICairoSVG | 已审查 | 2021-01-07 00:57 | 2024-09-14 01:42 |
| GHSA-P4Q6-QXJX-8JGP CVE-2021-21234 | Directory Traversal in spring-boot-actuator-logview | 高危 | Maveneu.hinsch:spring-boot-actuator-logview | 已审查 | 2021-01-06 01:29 | 2021-01-08 06:28 |
| GHSA-4W2V-Q235-VP99 CVE-2020-28168 | Axios vulnerable to Server-Side Request Forgery | 中危 | npmaxios | 已审查 | 2021-01-05 04:59 | 2022-09-15 04:36 |
| GHSA-8J9V-H2VP-2HHV CVE-2020-26293 | XSS in HtmlSanitizer | 低危 | NuGetHtmlSanitizer | 已审查 | 2021-01-05 02:22 | 2021-01-08 06:32 |
| GHSA-3329-PJWV-FJPG CVE-2020-26291 | Hostname spoofing via backslashes in URL | 中危 | npmurijs | 已审查 | 2020-12-31 07:40 | 2022-11-30 11:23 |
| GHSA-R2QC-W64X-6J54 CVE-2020-26296 | XSS in Vega | 低危 | npmvega | 已审查 | 2020-12-31 07:09 | 2021-01-08 06:32 |
| GHSA-VR8Q-G5C7-M54M CVE-2020-26247 | Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability | 中危 | RubyGemsnokogiri | 已审查 | 2020-12-31 02:35 | 2022-08-17 03:53 |
| GHSA-4W46-W44M-3JQ3 CVE-2020-26288 | Parse Server stores password in plain text | 低危 | npmparse-server | 已审查 | 2020-12-29 00:33 | 2021-01-08 06:32 |
| GHSA-WMFG-55F9-J8HQ CVE-2020-26282 | Server-Side Template Injection | 高危 | Mavencom.browserup:browserup-proxy | 已审查 | 2020-12-25 04:49 | 2020-12-25 04:48 |
| GHSA-R92X-F52R-X54G CVE-2020-26289 | regular expression denial of service (ReDoS) | 高危 | npmdate-and-time | 已审查 | 2020-12-25 04:49 | 2021-01-08 06:33 |
| GHSA-9F66-54XG-PC2C CVE-2020-26275 | Jupyter Server open redirect vulnerability | 中危 | PyPIjupyter-server | 已审查 | 2020-12-22 02:01 | 2026-05-20 04:24 |
| GHSA-8PFH-MM2G-HMC3 | Authenticated Server Side Request Forgery | 低危 | Packagistshopware/core+1 | 已审查 | 2020-12-22 02:01 | 2020-12-22 01:46 |