检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-H385-52J6-9984 CVE-2020-7670 | Withdrawn: HTTP Request Smuggling in Agoo 已撤回 | 中危 | RubyGemsagoo | 已审查 | 2020-10-21 03:15 | 2021-01-14 03:25 |
当前筛选结果 366,391 条 · 时间按北京时间显示
Denial of Service via Cache Flooding |
| 低危 |
Packagistshopware/core+1 |
| 已审查 |
| 2020-10-20 05:34 |
| 2020-10-20 05:34 |
| GHSA-8XV9-QCR9-WW9J | Authenticated XML External Entity Processing | 中危 | Packagistshopware/core+1 | 已审查 | 2020-10-20 05:32 | 2021-10-05 05:28 |
| GHSA-CWX2-736X-MF6W CVE-2020-15256 | Prototype pollution in object-path | 高危 | npmobject-path | 已审查 | 2020-10-20 04:55 | 2021-11-19 22:05 |
| GHSA-6GW4-X63H-5499 CVE-2020-15245 | Ability to switch customer email address on account detail page and stay verified | 中危 | Packagistsylius/sylius | 已审查 | 2020-10-20 04:40 | 2021-11-19 21:51 |
| GHSA-589W-HCCM-265X CVE-2020-15263 | Inline attribute values were not processed. | 高危 | Packagistorchid/platform | 已审查 | 2020-10-20 04:17 | 2021-01-08 06:50 |
| GHSA-4FC4-CHG7-H8GH CVE-2020-15262 | Unprotected dynamically loaded chunks | 低危 | npmwebpack-subresource-integrity | 已审查 | 2020-10-20 04:02 | 2021-11-19 22:40 |
| GHSA-XGH6-85XH-479P | Regular Expression Denial of Service in npm-user-validate | 低危 | npmnpm-user-validate | 已审查 | 2020-10-17 02:56 | 2020-10-17 02:56 |
| GHSA-8HXH-R6F7-JF45 | Memory exhaustion in http4s-async-http-client with large or malicious compressed responses | 低危 | Mavenorg.http4s:http4s-async-http-client_2.12+1 | 已审查 | 2020-10-17 01:03 | 2021-10-05 05:26 |
| GHSA-3X8C-FMPC-5RMQ CVE-2020-26891 | Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint | 中危 | PyPImatrix-synapse | 已审查 | 2020-10-17 00:56 | 2024-09-25 01:41 |
| GHSA-5HV6-MH8Q-Q9V8 CVE-2020-15252 | RCE in XWiki | 高危 | Mavenorg.xwiki.platform:xwiki-platform-oldcore | 已审查 | 2020-10-17 00:55 | 2021-11-19 22:41 |
| GHSA-G5VF-V6WF-7W2R CVE-2020-8929 | Ciphertext Malleability Issue in Tink Java | 中危 | Mavencom.google.crypto.tink:tink | 已审查 | 2020-10-16 08:51 | 2025-06-06 00:44 |
| GHSA-J257-JFVV-H3X5 CVE-2020-15251 | Privilege Escalation in Channelmgnt plug-in for Sopel | 中危 | PyPIsopel_plugins.channelmgnt+1 | 已审查 | 2020-10-14 01:30 | 2024-10-28 21:59 |
| GHSA-6R7X-HC8M-985R CVE-2020-9038 | Cross-site Scripting in Joplin | 中危 | npmjoplin | 已审查 | 2020-10-14 01:29 | 2022-01-05 03:44 |
| GHSA-269G-PWP5-87PP CVE-2020-15250 | TemporaryFolder on unix-like systems does not limit access to created files | 中危 | Mavenjunit:junit | 已审查 | 2020-10-13 01:33 | 2021-10-06 00:04 |
| GHSA-82RF-Q3PR-4F6P CVE-2020-26149 | Sensitive data exposure in NATS | 高危 | npmnats+1 | 已审查 | 2020-10-09 06:11 | 2023-09-12 04:18 |
| GHSA-VR9X-MM65-2438 CVE-2020-8178 | Command Injection in jison 已撤回 | 高危 | npmjison | 已审查 | 2020-10-09 05:38 | 2020-10-20 02:55 |
| GHSA-5822-PW57-VV37 | XSS vulnerability when listing users on add & modify server pages. | 中危 | Packagistpterodactyl/panel | 已审查 | 2020-10-09 04:13 | 2021-10-05 05:25 |
| GHSA-7733-HJV6-4H47 CVE-2020-15241 | Cross-Site Scripting in ternary conditional operator | 中危 | Packagisttypo3/cms+2 | 已审查 | 2020-10-09 03:55 | 2021-11-19 23:11 |
| GHSA-X56P-C8CG-Q435 CVE-2020-15242 | Open Redirect in Next.js versions | 中危 | npmnext | 已审查 | 2020-10-09 03:28 | 2021-10-07 05:27 |
| GHSA-55W9-C3G2-4RRH CVE-2012-5784 | Man-in-the-middle attack in Apache Axis | 中危 | Mavenaxis:axis+1 | 已审查 | 2020-10-08 01:51 | 2020-10-08 01:50 |
| GHSA-HWV5-W8GM-FQ9F CVE-2020-15239 | Directory Traversal vulnerability in GET/PUT allows attackers to Disclose Information or Write Files via a crafted GET/PUT request | 低危 | PyPIxmpp-http-upload | 已审查 | 2020-10-07 02:21 | 2024-11-20 02:08 |
| GHSA-56PC-6JQP-XQJ8 CVE-2020-15215 | Context isolation bypass in Electron | 低危 | npmelectron | 已审查 | 2020-10-07 01:46 | 2021-01-08 06:51 |
| GHSA-2Q4G-W47C-4674 CVE-2020-15174 | Unpreventable top-level navigation | 高危 | npmelectron | 已审查 | 2020-10-06 22:24 | 2021-11-19 22:44 |
| GHSA-5JJV-X4FQ-QJWP CVE-2020-15237 | Possible timing attack in derivation_endpoint | 中危 | RubyGemsshrine | 已审查 | 2020-10-05 23:48 | 2023-05-17 00:18 |