检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-PJXW-22XF-6PWC CVE-2018-16486 | Prototype Pollution in defaults-deep | 严重 | npmdefaults-deep | 已审查 | 2019-02-08 02:16 | 2023-09-13 05:05 |
| GHSA-GMXV-XF2Q-6J8M CVE-2018-16484 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
npmm-server |
| 已审查 |
| 2019-02-08 02:16 |
| 2023-09-14 03:48 |
| GHSA-WJ36-V8J4-PC7C CVE-2018-16483 | Authentication Bypass by Spoofing in express-cart | 高危 | npmexpress-cart | 已审查 | 2019-02-08 02:16 | 2022-09-15 06:42 |
| GHSA-CXMJ-QJV6-VX9P CVE-2018-16482 | mcstatic directory traversal vulnerability | 高危 | npmmcstatic | 已审查 | 2019-02-08 02:15 | 2023-09-13 04:46 |
| GHSA-5P26-HW7F-3CPR CVE-2018-16481 | Cross-Site Scripting in html-pages | 中危 | npmhtml-pages | 已审查 | 2019-02-08 02:14 | 2023-09-13 04:39 |
| GHSA-649C-X44H-4Q7V CVE-2018-16480 | Tnantoka/public XSS Vulnerability | 中危 | npmpublic | 已审查 | 2019-02-08 02:14 | 2023-09-12 02:35 |
| GHSA-7C9W-QMRQ-FF8R CVE-2018-16479 | Path Traversal in http-live-simulator | 高危 | npmhttp-live-simulator | 已审查 | 2019-02-08 02:14 | 2020-09-01 02:35 |
| GHSA-QRMC-FJ45-QFC2 CVE-2018-16492 | Prototype Pollution in extend | 中危 | npmextend | 已审查 | 2019-02-08 02:03 | 2026-01-23 05:48 |
| GHSA-FVXV-9XXR-H7WJ CVE-2018-11760 | Pyspark User Impersonation Vulnerability | 中危 | PyPIpyspark | 已审查 | 2019-02-08 02:02 | 2024-10-25 05:44 |
| GHSA-HHXM-4F85-RGR8 | High severity vulnerability that affects many_versioned_gem 已撤回 | 高危 | RubyGemsmany_versioned_gem | 已审查 | 2019-02-06 00:25 | 2020-06-17 05:40 |
| GHSA-MH24-7WVG-V88G CVE-2019-6802 | CRLF Injection in pypiserver | 中危 | PyPIpypiserver | 已审查 | 2019-01-31 04:56 | 2024-10-16 00:01 |
| GHSA-77RC-X84Q-PV4F CVE-2018-20245 | Improper Certificate Validation in Apache Airflow | 高危 | PyPIapache-airflow | 已审查 | 2019-01-26 00:19 | 2024-09-05 04:53 |
| GHSA-68WV-RJRM-576P CVE-2017-17835 | Cross-Site Request Forgery (CSRF) in Apache Airflow | 高危 | PyPIapache-airflow | 已审查 | 2019-01-26 00:19 | 2024-09-12 03:59 |
| GHSA-9GQG-3FXR-9HV7 CVE-2017-17836 | Apache Airflow vulnerable to XSS | 严重 | PyPIapache-airflow | 已审查 | 2019-01-26 00:19 | 2024-09-13 04:12 |
| GHSA-8FG4-J562-MJRC CVE-2017-15720 | Improper Input Validation in Apache Airflow resulting in Remote Code Execution | 高危 | PyPIapache-airflow | 已审查 | 2019-01-26 00:19 | 2024-09-10 05:31 |
| GHSA-3WC8-659G-R88Q CVE-2019-3774 | Low severity vulnerability that affects org.springframework.batch:spring-batch-core | 低危 | Mavenorg.springframework.batch:spring-batch-core | 已审查 | 2019-01-26 00:18 | 2025-09-23 23:16 |
| GHSA-8222-6FC8-MHVF CVE-2019-3773 | Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml | 严重 | Mavenorg.springframework.ws:spring-ws+1 | 已审查 | 2019-01-26 00:18 | 2021-06-16 00:59 |
| GHSA-WR5R-M8PC-85J9 CVE-2019-3772 | Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml | 低危 | Mavenorg.springframework.integration:spring-integration-ws+1 | 已审查 | 2019-01-26 00:18 | 2024-03-05 07:42 |
| GHSA-6QVP-R6R3-9P7H CVE-2018-14404 | Nokogiri NULL Pointer Dereference | 高危 | RubyGemsnokogiri | 已审查 | 2019-01-17 22:05 | 2025-12-05 00:20 |
| GHSA-PH58-4VRJ-W6HR CVE-2018-20677 | bootstrap Cross-site Scripting vulnerability | 中危 | Mavenbootstrap+3 | 已审查 | 2019-01-17 21:57 | 2024-08-06 00:31 |
| GHSA-3MGP-FX93-9XV5 CVE-2018-20676 | XSS vulnerability that affects bootstrap | 中危 | Mavenbootstrap+3 | 已审查 | 2019-01-17 21:57 | 2024-08-06 00:32 |
| GHSA-4P24-VMCR-4GQJ CVE-2016-10735 | Bootstrap Cross-site Scripting vulnerability | 中危 | Mavenbootstrap+4 | 已审查 | 2019-01-17 21:57 | 2024-08-06 00:29 |
| GHSA-WJXJ-F8RG-99WX CVE-2018-1320 | Improper Input Validation in Apache Thrift | 高危 | Mavenorg.apache.thrift:libthrift | 已审查 | 2019-01-17 21:56 | 2024-03-05 04:36 |
| GHSA-VX85-MJ8C-4QM6 CVE-2018-11798 | Apache Thrift Node.js static web server sandbox escape | 中危 | Mavenorg.apache.thrift:libthrift | 已审查 | 2019-01-17 21:56 | 2023-09-12 02:30 |
| GHSA-JHJH-GHWX-6H7R CVE-2017-1002157 | modulemd uses an unsafe function for processing externally provided data | 严重 | PyPImodulemd | 已审查 | 2019-01-17 21:56 | 2024-09-25 04:48 |