scratch-svg-renderer是Scratch团队的一个应用于转换 SVG 成 DOM 元素的代码库。 scratch-svg-renderer 0.2.0-prerelease.20201019174008之前版本存在安全漏洞,该漏洞源于loadString函数没有正确地转义SVG,可以使用它通过transformMeasurements函数将任意元素注入到DOM中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | scratch-svg-renderer | unspecified ~ 0.2.0-prerelease.20201019174008 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-27611 | BigBlueButton 加密问题漏洞 | |
| CVE-2020-17381 | Ghisler Total Commander 安全漏洞 | |
| CVE-2020-26895 | Lightning Network Daemon 安全漏洞 | |
| CVE-2020-26896 | Lightning Network Daemon 安全漏洞 | |
| CVE-2020-25820 | BigBlueButton 代码问题漏洞 | |
| CVE-2020-27602 | BigBlueButton 注入漏洞 | |
| CVE-2020-27606 | BigBlueButton 安全漏洞 | |
| CVE-2020-27608 | BigBlueButton 跨站脚本漏洞 | |
| CVE-2020-27610 | BigBlueButton 信息泄露漏洞 | |
| CVE-2020-27612 | BigBlueButton 信息泄露漏洞 | |
| CVE-2020-27613 | BigBlueButton 安全漏洞 | |
| CVE-2020-17355 | Arista Networks Arista EOS 安全漏洞 | |
| CVE-2020-27609 | BigBlueButton 安全漏洞 | |
| CVE-2020-27607 | BigBlueButton 安全漏洞 | |
| CVE-2020-27605 | BigBlueButton 安全漏洞 | |
| CVE-2020-27604 | BigBlueButton 安全漏洞 | |
| CVE-2020-27603 | BigBlueButton 安全漏洞 | |
| CVE-2020-27601 | BigBlueButton 安全漏洞 | |
| CVE-2018-11764 | Apache Hadoop 访问控制错误漏洞 | |
| CVE-2020-27344 | WordPress cm-download-manager 跨站脚本漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet