检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W7Q9-P3JQ-FMHM CVE-2020-8175 | Uncontrolled resource consumption in jpeg-js | 中危 | npmjpeg-js | 已审查 | 2020-07-27 23:46 | 2023-09-09 06:35 |
| GHSA-F7F4-HQP2-7PRC CVE-2018-21036 | Improper Input Validation in sails-hook-sockets |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
npmsails-hook-sockets |
| 已审查 |
| 2020-07-25 04:10 |
| 2021-09-23 05:11 |
| GHSA-WVH7-5P38-2QFC | Storing Password in Local Storage | 中危 | npmparse | 已审查 | 2020-07-24 02:20 | 2021-09-23 05:05 |
| GHSA-V7M9-9497-P9GR CVE-2020-15110 | Possible pod name collisions in jupyterhub-kubespawner | 高危 | PyPIjupyterhub-kubespawner | 已审查 | 2020-07-23 07:07 | 2024-09-25 04:43 |
| GHSA-236H-RQV8-8Q73 CVE-2020-15126 | GraphQL: Security breach on Viewer query | 中危 | npmparse-server | 已审查 | 2020-07-23 07:06 | 2023-10-26 19:33 |
| GHSA-2473-9HGQ-J7XW CVE-2020-15118 | Cross-Site Scripting in Wagtail | 高危 | PyPIwagtail | 已审查 | 2020-07-21 01:50 | 2024-11-19 23:50 |
| GHSA-XP63-6VF5-XF3V CVE-2020-15123 | Command injection in codecov (npm package) | 中危 | npmcodecov | 已审查 | 2020-07-21 01:20 | 2021-01-08 07:47 |
| GHSA-P6MC-M468-83GW CVE-2020-8203 | Prototype Pollution in lodash | 高危 | npmlodash+7 | 已审查 | 2020-07-16 03:15 | 2025-08-13 05:43 |
| GHSA-43JJ-2RWC-2M3F CVE-2019-14273 | Broken access control on files | 中危 | Packagistsilverstripe/framework | 已审查 | 2020-07-16 01:38 | 2024-02-02 03:02 |
| GHSA-7XCX-6WJH-7XP2 | Command Injection in standard-version | 中危 | npmstandard-version | 已审查 | 2020-07-14 05:34 | 2021-09-23 05:03 |
| GHSA-VHR6-PVJM-9QWF CVE-2020-15105 | User passwords are stored in clear text in the Django session | 中危 | PyPIdjango-two-factor-auth | 已审查 | 2020-07-11 04:55 | 2024-09-17 05:33 |
| GHSA-2JPM-827P-J44G CVE-2020-15092 | Stored XSS in TimelineJS3 | 高危 | npm@knight-lab/timelinejs | 已审查 | 2020-07-10 02:28 | 2021-01-08 07:47 |
| GHSA-9H4G-27M8-QJRG CVE-2020-15779 | Path Traversal in socket.io-file | 高危 | npmsocket.io-file | 已审查 | 2020-07-08 03:24 | 2021-09-23 04:28 |
| GHSA-JMQM-F2GX-4FJV | Sensitive information exposure through logs in npm-registry-fetch | 中危 | npmnpm-registry-fetch | 已审查 | 2020-07-08 02:59 | 2021-09-23 03:00 |
| GHSA-93F3-23RQ-PJFP CVE-2020-15095 | npm CLI exposing sensitive information through logs | 中危 | npmnpm | 已审查 | 2020-07-08 02:56 | 2022-08-11 07:59 |
| GHSA-MM44-WC5P-WQHQ | Denial of service due to reference expansion in versions earlier than 4.0 | 高危 | Mavencom.upokecenter:cbor | 已审查 | 2020-07-08 00:45 | 2022-01-19 07:05 |
| GHSA-CR3X-7M39-C6JQ CVE-2020-8163 | Remote code execution via user-provided local names in ActionView | 高危 | RubyGemsactionview | 已审查 | 2020-07-08 00:34 | 2023-07-06 04:22 |
| GHSA-XQ5J-GW7F-JGJ8 CVE-2020-8167 | CSRF Vulnerability in rails-ujs | 中危 | RubyGemsactionview | 已审查 | 2020-07-08 00:34 | 2023-08-08 23:14 |
| GHSA-WWGF-3XP7-CXJ4 | Potentially sensitive data exposure in Symfony Web Socket Bundle | 中危 | Packagistgos/web-socket-bundle | 已审查 | 2020-07-08 00:33 | 2021-09-23 04:22 |
| GHSA-W534-Q4XF-H5V2 CVE-2020-15231 | XSS in Mapfish Print relating to JSONP support | 低危 | Mavenorg.mapfish.print:print-lib+2 | 已审查 | 2020-07-08 00:32 | 2021-01-08 07:47 |
| GHSA-VJV6-GQ77-3MJW CVE-2020-15232 | XXE attack in Mapfish Print | 严重 | Mavenorg.mapfish.print:print-lib+2 | 已审查 | 2020-07-08 00:32 | 2023-06-28 04:27 |
| GHSA-F9MQ-JPH6-9MHM CVE-2020-4075 | Arbitrary file read via window-open IPC in Electron | 中危 | npmelectron | 已审查 | 2020-07-07 08:01 | 2021-01-08 07:48 |
| GHSA-H9JC-284H-533G CVE-2020-4077 | Context isolation bypass via contextBridge in Electron | 高危 | npmelectron | 已审查 | 2020-07-07 08:01 | 2021-01-08 07:48 |
| GHSA-M93V-9QJC-3G79 CVE-2020-4076 | Context isolation bypass via leaked cross-context objects in Electron | 高危 | npmelectron | 已审查 | 2020-07-07 08:01 | 2021-01-08 07:48 |
| GHSA-6VRV-94JV-CRRG CVE-2020-15096 | Context isolation bypass via Promise in Electron | 低危 | npmelectron | 已审查 | 2020-07-07 08:01 | 2021-01-08 07:48 |