检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9X9J-836W-8F55 CVE-2020-1026 | Incorrect Calculation in the MSR JavaScript Cryptography Library | 高危 | npmmsrcrypto | 已审查 | 2022-01-07 03:44 | 2021-10-21 06:19 |
| GHSA-6QJ8-C27W-RP33 CVE-2019-17557 | Cross-site scripting in Apache Syncome EndUser |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Mavenorg.apache.syncope.client:syncope-client-enduser |
| 已审查 |
| 2022-01-07 03:38 |
| 2021-05-26 04:49 |
| GHSA-P479-RWHP-RWJX CVE-2021-21667 | Stored XSS vulnerability in Jenkins Scriptler Plugin | 中危 | Mavenorg.jenkins-ci.plugins:scriptler | 已审查 | 2022-01-07 02:45 | 2023-10-27 23:19 |
| GHSA-5C6C-W4C4-VGVX CVE-2021-21668 | Stored XSS vulnerability in Jenkins Scriptler Plugin | 中危 | Mavenorg.jenkins-ci.plugins:scriptler | 已审查 | 2022-01-07 02:45 | 2023-10-27 23:08 |
| GHSA-C7FH-CHF7-JR5X CVE-2021-29061 | ReDOS in Vfsjfilechooser2 | 高危 | Mavencom.github.fracpete:vfsjfilechooser2 | 已审查 | 2022-01-07 02:44 | 2022-01-07 02:36 |
| GHSA-G23V-P5JQ-JVH4 CVE-2021-30468 | Infinite loop in Apache CFX | 高危 | Mavenorg.apache.cxf:apache-cxf+1 | 已审查 | 2022-01-07 02:37 | 2021-06-24 21:23 |
| GHSA-9328-7PCW-VW69 CVE-2020-1692 | Cross-Site Request Forgery in Moodle | 中危 | Packagistmoodle/moodle | 已审查 | 2022-01-07 02:34 | 2022-01-05 00:32 |
| GHSA-QV7G-J98V-8PP7 CVE-2021-41236 | XSS vulnerability on email template preview page | 中危 | Packagistoro/platform | 已审查 | 2022-01-07 02:34 | 2022-01-05 01:51 |
| GHSA-HP68-XHVJ-X6J6 CVE-2021-43843 | jsx-slack insufficient patch for CVE-2021-43838 ReDoS | 中危 | npmjsx-slack | 已审查 | 2022-01-07 02:34 | 2022-08-12 02:43 |
| GHSA-H3FG-H5V3-VF8M CVE-2021-43846 | CSRF forgery protection bypass in solidus_frontend | 中危 | RubyGemssolidus_frontend | 已审查 | 2022-01-07 02:33 | 2023-05-05 03:59 |
| GHSA-83X4-9CWR-5487 CVE-2021-4133 | Improper Authorization in Keycloak | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2022-01-07 02:32 | 2022-02-03 00:07 |
| GHSA-5Q7Q-QQW2-HJQ7 CVE-2021-43853 | AjaxNetProfessional deserializes arbitrary JavaScript objects | 高危 | NuGetAjaxNetProfessional | 已审查 | 2022-01-07 02:32 | 2022-08-12 02:44 |
| GHSA-3QPM-H9CH-PX3C | Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library | 严重 | Mavenorg.powernukkit:powernukkit | 已审查 | 2022-01-07 02:31 | 2022-01-05 06:06 |
| GHSA-F854-HPXV-CW9R CVE-2021-43839 | Drainage of FeeCollector's Block Transaction Fees in cronos | 高危 | Gogithub.com/crypto-org-chain/cronos+2 | 已审查 | 2022-01-07 02:30 | 2022-01-07 04:21 |
| GHSA-GP6J-VX54-5PMF | Incorrect validation of parties IDs leaks secret keys in Secret-sharing scheme | 严重 | Gogithub.com/keep-network/keep-ecdsa | 已审查 | 2022-01-07 02:30 | 2022-01-05 06:41 |
| GHSA-JX5Q-G37M-H5HJ CVE-2021-43852 | Client-Side JavaScript Prototype Pollution in oro/platform | 中危 | Packagistoro/platform | 已审查 | 2022-01-07 02:29 | 2022-01-05 06:46 |
| GHSA-F8M6-H2C7-8H9X CVE-2021-43854 | Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize) | 高危 | PyPInltk | 已审查 | 2022-01-07 01:38 | 2024-09-26 22:17 |
| GHSA-MVFF-H3CJ-WJ9C CVE-2021-43816 | Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux | 高危 | Gogithub.com/containerd/containerd | 已审查 | 2022-01-07 01:36 | 2022-04-05 04:40 |
| GHSA-9W7F-M4J4-J3XW CVE-2021-43857 | Gerapy may cause remote code execution | 严重 | PyPIgerapy | 已审查 | 2022-01-07 01:36 | 2024-09-21 01:52 |
| GHSA-53XV-C2HX-5W6Q CVE-2021-45459 | Command Injection in node-windows | 严重 | npmnode-windows | 已审查 | 2022-01-06 04:39 | 2022-03-31 05:13 |
| GHSA-8XX9-RXRJ-2M2W CVE-2021-4139 | Cross-site Scripting in pimcore | 中危 | Packagistpimcore/pimcore | 已审查 | 2022-01-06 04:35 | 2022-01-05 05:18 |
| GHSA-HX77-5P88-F92R CVE-2021-4131 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | 高危 | Packagistremdex/livehelperchat | 已审查 | 2022-01-06 04:33 | 2022-01-05 04:21 |
| GHSA-F7XW-46VH-5JW2 CVE-2021-4132 | livehelperchat is vulnerable to Cross-site Scripting | 中危 | Packagistremdex/livehelperchat | 已审查 | 2022-01-06 04:33 | 2022-01-05 04:12 |
| GHSA-4W23-C97G-FQ5V CVE-2021-4130 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | 高危 | Packagistsnipe/snipe-it | 已审查 | 2022-01-06 04:33 | 2022-01-05 04:20 |
| GHSA-RQ96-QHC5-VM4R CVE-2021-44145 | Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFi | 中危 | Mavenorg.apache.nifi:nifi | 已审查 | 2022-01-06 01:33 | 2022-01-05 04:18 |