检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W3V3-CXQ5-9VR4 CVE-2022-0179 | Incorrect Default Permissions and Improper Access Control in snipe-it | 中危 | Packagistsnipe/snipe-it | 已审查 | 2022-01-22 07:58 | 2023-07-01 04:03 |
| GHSA-6W5M-JGC5-8CGC CVE-2022-0159 | orchardcore is vulnerable to Cross-site Scripting |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
NuGetOrchardCore |
| 已审查 |
| 2022-01-22 07:57 |
| 2022-01-20 22:53 |
| GHSA-QRPM-P2H7-HRV2 CVE-2021-23566 | Exposure of Sensitive Information to an Unauthorized Actor in nanoid | 中危 | npmnanoid | 已审查 | 2022-01-22 07:57 | 2025-11-05 00:35 |
| GHSA-J545-FRH3-R9GQ CVE-2022-0224 | SQL Injection in dolibarr | 高危 | Packagistdolibarr/dolibarr | 已审查 | 2022-01-22 07:56 | 2022-11-18 04:14 |
| GHSA-R683-J2X4-V87G CVE-2022-0235 | node-fetch forwards secure headers to untrusted sites | 高危 | npmnode-fetch | 已审查 | 2022-01-22 07:55 | 2023-09-08 02:38 |
| GHSA-WRP6-9W7F-3WXG CVE-2021-4170 | calibre-web is vulnerable to Cross-site Scripting | 中危 | PyPIcalibreweb | 已审查 | 2022-01-22 07:55 | 2024-11-20 00:15 |
| GHSA-WPPJ-3PJR-9W79 CVE-2021-4080 | crater is vulnerable to Unrestricted Upload of File with Dangerous Type | 高危 | Packagistbytefury/crater | 已审查 | 2022-01-22 07:55 | 2022-01-20 23:08 |
| GHSA-728C-42PC-FWXG CVE-2022-0242 | Unrestricted Upload of File with Dangerous Type in Crater | 高危 | Packagistbytefury/crater | 已审查 | 2022-01-22 07:54 | 2022-01-19 22:08 |
| GHSA-C6RP-XVQV-MWMF CVE-2021-33040 | Cross-site Scripting in epubjs | 中危 | npmepubjs | 已审查 | 2022-01-22 07:52 | 2023-09-13 05:00 |
| GHSA-VV38-4XCJ-Q4RW CVE-2021-42357 | Cross-site Scripting in Apache Knox SSO | 中危 | Mavenorg.apache.knox:gateway-service-knoxsso | 已审查 | 2022-01-22 07:52 | 2022-01-26 04:49 |
| GHSA-V567-Q267-PHPG CVE-2022-0257 | pimcore is vulnerable to Cross-site Scripting | 中危 | Packagistpimcore/pimcore | 已审查 | 2022-01-22 07:50 | 2022-01-26 04:49 |
| GHSA-VJ9X-W7CH-F46P CVE-2022-0258 | pimcore is vulnerable to SQL Injection | 高危 | Packagistpimcore/pimcore | 已审查 | 2022-01-22 07:50 | 2022-01-19 22:22 |
| GHSA-5R9V-8W62-R26J CVE-2022-0253 | livehelperchat is vulnerable to Cross-site Scripting | 中危 | Packagistremdex/livehelperchat | 已审查 | 2022-01-22 07:48 | 2022-01-26 03:13 |
| GHSA-57HG-26H7-9QGV CVE-2022-0256 | pimcore is vulnerable to Cross-site Scripting | 中危 | Packagistpimcore/pimcore | 已审查 | 2022-01-22 07:48 | 2022-01-26 04:49 |
| GHSA-73Q9-7PWJ-GM46 CVE-2021-3862 | icecoder is vulnerable to Cross-site Scripting | 中危 | Packagisticecoder/icecoder | 已审查 | 2022-01-22 07:46 | 2022-01-19 22:28 |
| GHSA-WXR6-29PV-CH68 CVE-2021-4164 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | 高危 | PyPIcalibreweb | 已审查 | 2022-01-22 07:44 | 2022-01-19 22:24 |
| GHSA-XP7P-3GX7-J6WX CVE-2021-4171 | calibre-web is vulnerable to Business Logic Errors | 严重 | PyPIcalibreweb | 已审查 | 2022-01-22 07:44 | 2022-01-26 03:12 |
| GHSA-XQXM-2RPM-3889 CVE-2022-21683 | Comment reply notifications sent to incorrect users | 中危 | PyPIwagtail | 已审查 | 2022-01-22 07:43 | 2024-11-20 00:03 |
| GHSA-RHQ2-3VR9-6MCR CVE-2021-43831 | Files on the host computer can be accessed from the Gradio interface | 严重 | PyPIgradio | 已审查 | 2022-01-22 07:43 | 2024-11-19 00:26 |
| GHSA-75VW-3M5V-FPRH CVE-2022-0239 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | 严重 | Mavenedu.stanford.nlp:stanford-corenlp | 已审查 | 2022-01-22 07:43 | 2026-04-15 07:55 |
| GHSA-GH88-3PXP-6FM8 CVE-2021-23567 | Infinite Loop in colors.js | 高危 | npmcolors | 已审查 | 2022-01-22 07:39 | 2022-01-22 05:04 |
| GHSA-883X-6FCH-6WJX CVE-2024-23683 | Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in Ares | 高危 | Mavende.tum.in.ase:artemis-java-test-sandbox | 已审查 | 2022-01-22 07:39 | 2026-01-23 04:31 |
| GHSA-FPJ7-9XM6-8HGR CVE-2022-23106 | Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin | 低危 | Mavenio.jenkins:configuration-as-code | 已审查 | 2022-01-22 07:38 | 2023-05-24 22:00 |
| GHSA-RVH4-G2RJ-HR9C CVE-2022-23107 | Path Traversal in Jenkins Warnings Next Generation Plugin | 高危 | Mavenio.jenkins.plugins:warnings-ng | 已审查 | 2022-01-22 07:38 | 2023-10-28 00:10 |
| GHSA-P92Q-7FHH-MQ35 CVE-2022-20612 | Cross-Site Request Forgery in Jenkins | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2022-01-22 07:37 | 2023-10-28 03:01 |