检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QF6H-P3MR-VMH5 | Duplicate Advisory: Code injection in Directus 已撤回 | 中危 | npmdirectus | 已审查 | 2024-08-15 11:30 | 2025-03-22 08:35 |
| GHSA-4HQ2-RPGC-R8R7 |
当前筛选结果 998 条 · 时间按北京时间显示
Withdrawn Advisory: Litestar has an environment Variable injection in `docs-preview.yml` workflow 已撤回 |
| 高危 |
PyPIlitestar |
| 已审查 |
| 2024-08-10 03:22 |
| 2024-08-21 02:37 |
| GHSA-W7C4-5W4F-JM3G CVE-2024-36117 | Duplicate Advisory: Reposilite Arbitrary File Read vulnerability 已撤回 | 高危 | Mavencom.reposilite:reposilite-backend | 已审查 | 2024-08-06 05:29 | 2024-11-06 00:19 |
| GHSA-8C64-Q78Q-87R6 | Duplicate Advisory: Juju leaks of the sensitive context ID 已撤回 | 高危 | Gogithub.com/juju/juju | 已审查 | 2024-07-29 23:30 | 2024-08-06 01:18 |
| GHSA-X72P-G37Q-4XR9 CVE-2024-40430 | Withdrawn: SFTPGo's JWT implmentation lacks certain security measures 已撤回 | 中危 | Gogithub.com/drakkan/sftpgo/v2 | 已审查 | 2024-07-22 17:31 | 2024-08-01 02:42 |
| GHSA-VC8W-JR9V-VJ7F CVE-2024-6531 | Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability 已撤回 | 中危 | Mavenbootstrap+4 | 已审查 | 2024-07-12 02:31 | 2025-10-10 04:55 |
| GHSA-9MVJ-F7W8-PVH2 CVE-2024-6484 | Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability 已撤回 | 中危 | Mavenbootstrap+5 | 已审查 | 2024-07-12 02:31 | 2025-09-12 00:19 |
| GHSA-52JW-F3JQ-HHWG | Duplicate Advisory: Login by Auth0 plugin for WordPress vulnerable to Reflected Cross-Site Scripting 已撤回 | 中危 | Packagistauth0/wordpress | 已审查 | 2024-07-10 17:30 | 2024-07-12 03:50 |
| GHSA-HF29-9HFH-W63J | Duplicate Advisory: Gogs allows argument injection during the previewing of changes 已撤回 | 严重 | Gogithub.com/gogs/gogs | 已审查 | 2024-07-05 02:31 | 2024-12-24 04:37 |
| GHSA-8MM6-WMPP-MMM3 | Duplicate Advisory: Gogs allows argument injection during the tagging of a new release 已撤回 | 高危 | Gogithub.com/gogs/gogs | 已审查 | 2024-07-05 02:31 | 2024-12-24 04:36 |
| GHSA-P69R-V3H4-RJ4F | Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930 已撤回 | 严重 | Gogithub.com/gogs/gogs | 已审查 | 2024-07-05 02:31 | 2024-12-24 04:37 |
| GHSA-2VGJ-3PVG-XH4W | Duplicate Advisory: Gogs allows deletion of internal files 已撤回 | 严重 | Gogithub.com/gogs/gogs | 已审查 | 2024-07-05 02:31 | 2024-12-24 04:37 |
| GHSA-9V2F-6VCG-3HGV CVE-2024-39236 | Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py 已撤回 | 严重 | PyPIGradio | 已审查 | 2024-07-02 05:31 | 2026-06-06 01:54 |
| GHSA-4WM9-3QMV-GVXJ CVE-2024-38993 | jsonic was discovered to contain a prototype pollution via the function empty. 已撤回 | 严重 | npmjsonic | 已审查 | 2024-07-01 23:32 | 2024-07-13 03:08 |
| GHSA-GMRM-8FX4-66X7 | Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials 已撤回 | 低危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2024-06-18 20:30 | 2024-09-10 05:31 |
| GHSA-3MWC-2CJ7-GX8C CVE-2024-5389 | lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management 已撤回 | 中危 | npmlunary | 已审查 | 2024-06-10 08:30 | 2024-11-25 23:40 |
| GHSA-W5XM-MX47-V7C8 CVE-2024-4146 | lunary-ai/lunary allows users unauthorized access to projects 已撤回 | 严重 | npmlunary | 已审查 | 2024-06-09 05:30 | 2024-11-19 03:40 |
| GHSA-CR7J-RWMV-VGCH CVE-2024-36811 | Duplicate Advisory: aimeos-core arbitrary file upload vulnerability 已撤回 | 高危 | Packagistaimeos/aimeos-core | 已审查 | 2024-06-08 05:31 | 2024-06-21 00:34 |
| GHSA-RPX8-FG6W-RM6X CVE-2024-5478 | Withdrawn Advisory: lunary-ai/lunary XSS in SAML metadata endpoint 已撤回 | 高危 | npmlunary | 已审查 | 2024-06-07 05:30 | 2025-06-21 04:01 |
| GHSA-2HFW-W739-P7X5 | Duplicate Advisory: nano-id reduced entropy due to inadequate character set usage 已撤回 | 严重 | crates.ionano-id | 已审查 | 2024-06-05 01:49 | 2026-02-03 06:27 |
| GHSA-4VRX-8PHJ-X3MG | Duplicate Advisory: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR) 已撤回 | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2024-06-04 02:30 | 2024-07-31 07:52 |
| GHSA-JRR7-64M9-X984 | Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass 已撤回 | 高危 | Gogithub.com/snapcore/snapd | 已审查 | 2024-06-01 05:30 | 2025-01-17 01:19 |
| GHSA-75MX-CHCF-2Q32 | Duplicate Advisory: TYPO3 Cross-Site Scripting vulnerability in typolinks 已撤回 | 中危 | Packagisttypo3/cms | 已审查 | 2024-05-31 05:25 | 2026-02-04 01:54 |
| GHSA-V7Q3-5RQM-X7M9 CVE-2024-23952 | Duplicate Advisory: Apache Superset uncontrolled resource consumption 已撤回 | 中危 | PyPIapache-superset | 已审查 | 2024-05-31 04:53 | 2024-06-29 00:18 |
| GHSA-7FPJ-WC8V-9CGC | Duplicate Advisory: terminal42/contao-tablelookupwizard possible SQL injection in widget field value 已撤回 | 严重 | Packagistterminal42/contao-tablelookupwizard | 已审查 | 2024-05-30 21:12 | 2026-01-24 06:53 |