检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VFQ6-HQ5R-27R6 CVE-2019-19844 | Django Potential account hijack via password reset form | 严重 | PyPIDjango | 已审查 | 2020-01-17 06:35 | 2024-09-20 23:01 |
| GHSA-7FCJ-PQ9J-WH2R CVE-2019-16784 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
PyPIPyInstaller |
| 已审查 |
| 2020-01-17 06:18 |
| 2024-10-23 23:54 |
| GHSA-R5GM-4P5W-PQ2P CVE-2019-19576 | Remote code execution in verot/class.upload.php | 严重 | Packagistverot/class.upload.php | 已审查 | 2020-01-17 06:17 | 2026-07-21 23:02 |
| GHSA-JGJC-332C-8CMC CVE-2019-18622 | SQL injection in phpMyAdmin | 严重 | Packagistphpmyadmin/phpmyadmin | 已审查 | 2020-01-17 05:56 | 2021-08-20 00:24 |
| GHSA-8J72-P2WM-6738 CVE-2020-5223 | Persistent XSS vulnerability in filename of attached file in PrivateBin | 中危 | Packagistprivatebin/privatebin | 已审查 | 2020-01-15 04:19 | 2021-01-15 01:43 |
| GHSA-V62J-FCXQ-J239 CVE-2019-10070 | Stored XSS in Apache Atlas | 中危 | Mavenorg.apache.atlas:apache-atlas | 已审查 | 2020-01-09 01:26 | 2021-08-20 00:23 |
| GHSA-GF8J-V8X5-H9QP CVE-2019-18857 | XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes | 高危 | Packagistenshrined/svg-sanitize | 已审查 | 2020-01-09 01:15 | 2022-02-17 06:20 |
| GHSA-M8P2-495H-CCMH CVE-2019-10219 | The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks | 中危 | Mavenorg.hibernate:hibernate-validator+1 | 已审查 | 2020-01-09 01:01 | 2025-09-13 04:10 |
| GHSA-769F-539V-F5JG | PrestaShop gamification module ZIP archives were vulnerable from CVE-2017-9841 | 高危 | Packagistprestashop/gamification | 已审查 | 2020-01-08 11:10 | 2020-01-08 11:10 |
| GHSA-WQQ8-MQJ9-697F | PrestaShop autoupgrade module ZIP archives were vulnerable from CVE-2017-9841 | 高危 | Packagistprestashop/autoupgrade | 已审查 | 2020-01-08 11:10 | 2020-01-08 11:06 |
| GHSA-F884-GM86-CG3Q | PrestaShop module ps_facetedsearch might be vulnerable from CVE-2017-9841 | 高危 | Packagistprestashop/ps_facetedsearch | 已审查 | 2020-01-08 01:20 | 2020-01-08 01:20 |
| GHSA-968F-66R5-5V74 CVE-2019-16789 | HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers (Follow-up) | 中危 | PyPIwaitress | 已审查 | 2020-01-07 02:44 | 2024-11-19 21:58 |
| GHSA-92VM-WFM5-MXVV CVE-2016-1000236 | cookie-signature Timing Attack | 中危 | npmcookie-signature | 已审查 | 2020-01-07 02:44 | 2022-08-04 05:36 |
| GHSA-2QRG-X229-3V8Q CVE-2019-17571 | Deserialization of Untrusted Data in Log4j | 严重 | Mavenlog4j:log4j+1 | 已审查 | 2020-01-07 02:43 | 2026-06-09 18:22 |
| GHSA-FXPH-Q3J8-MV87 CVE-2017-5645 | Deserialization of Untrusted Data in Log4j | 严重 | Mavenorg.apache.logging.log4j:log4j+1 | 已审查 | 2020-01-07 02:43 | 2022-04-02 04:26 |
| GHSA-H47J-HC6X-H3QQ CVE-2019-10758 | Remote Code Execution Vulnerability in NPM mongo-express | 严重 | npmmongo-express | 已审查 | 2019-12-31 03:30 | 2025-10-23 01:44 |
| GHSA-HH3J-X4MC-G48R CVE-2019-12418 | Insufficiently Protected Credentials in Apache Tomcat | 高危 | Mavenorg.apache.tomcat.embed:tomcat-embed-core | 已审查 | 2019-12-27 02:22 | 2022-04-20 02:42 |
| GHSA-9XCJ-C8CR-8C3C CVE-2019-17563 | In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack | 高危 | Mavenorg.apache.tomcat.embed:tomcat-embed-core | 已审查 | 2019-12-27 02:22 | 2022-10-08 04:34 |
| GHSA-W457-6Q6X-CGP9 CVE-2019-19919 | Prototype Pollution in handlebars | 严重 | npmbootstrap-wysihtml5-rails+1 | 已审查 | 2019-12-27 01:58 | 2022-06-07 01:16 |
| GHSA-M5FF-3WJ3-8PH4 | HTTP Request Smuggling: Invalid whitespace characters in headers in Waitress | 高危 | PyPIwaitress | 已审查 | 2019-12-27 00:34 | 2019-12-27 00:34 |
| GHSA-4PPP-GPCR-7QF6 CVE-2019-16792 | HTTP Request Smuggling: Content-Length Sent Twice in Waitress | 严重 | PyPIwaitress | 已审查 | 2019-12-21 07:04 | 2026-01-23 06:34 |
| GHSA-G2XC-35JW-C63P CVE-2019-16786 | HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress | 中危 | PyPIwaitress | 已审查 | 2019-12-21 07:04 | 2024-11-19 21:57 |
| GHSA-PG36-WPM5-G57P CVE-2019-16785 | HTTP Request Smuggling: LF vs CRLF handling in Waitress | 中危 | PyPIwaitress | 已审查 | 2019-12-21 07:03 | 2024-11-19 21:55 |
| GHSA-HRQR-HXPP-CHR3 CVE-2019-16782 | Possible Information Leak / Session Hijack Vulnerability in Rack | 中危 | RubyGemsrack | 已审查 | 2019-12-19 03:01 | 2025-02-14 02:33 |
| GHSA-JC43-QRRP-98F5 CVE-2019-19714 | Insert tag injection in the Contao login module | 中危 | Packagistcontao/contao+1 | 已审查 | 2019-12-18 06:53 | 2024-04-23 02:41 |