检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-CXG7-84WP-8PCQ CVE-2021-4117 | YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product | 中危 | Packagistyetiforce/yetiforce-crm | 已审查 | 2021-12-17 05:01 | 2022-08-12 02:47 |
| GHSA-FWH7-V4GF-XV7W CVE-2021-4116 | yetiforcecrm is vulnerable to Cross-site Scripting |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistyetiforce/yetiforce-crm |
| 已审查 |
| 2021-12-17 05:00 |
| 2022-01-03 23:55 |
| GHSA-9C5C-5J4H-8Q2C CVE-2021-4119 | BookStack is vulnerable to Improper Access Control. | 中危 | Packagistssddanbrown/bookstack | 已审查 | 2021-12-17 03:40 | 2022-08-12 02:45 |
| GHSA-Q6GQ-997W-F55G CVE-2020-16845 | Withdrawn Advisory: Infinite loop in xz 已撤回 | 高危 | Gogithub.com/ulikunitz/xz | 已审查 | 2021-12-17 03:16 | 2025-10-15 03:37 |
| GHSA-J5QG-W9JG-3WG3 | Inability to de-op players if listed in ops.txt with non-lowercase letters | 低危 | Packagistpocketmine/pocketmine-mp | 已审查 | 2021-12-17 02:53 | 2021-12-16 23:47 |
| GHSA-HWVM-VFW8-93MW | Vulnerable dependency in XTDB connector | 中危 | Mavenorg.odpi.egeria:egeria-connector-xtdb | 已审查 | 2021-12-17 02:53 | 2021-12-17 02:40 |
| GHSA-2MQV-4J3R-VJVP CVE-2021-43812 | Open redirect in @auth0/nextjs-auth0 | 中危 | npm@auth0/nextjs-auth0 | 已审查 | 2021-12-17 02:52 | 2021-12-17 02:42 |
| GHSA-RP2C-JRGP-CVR8 CVE-2021-23562 | Code injection in plupload | 中危 | npmplupload | 已审查 | 2021-12-16 23:32 | 2021-12-07 06:08 |
| GHSA-8C9X-WFGJ-V78W CVE-2021-4000 | Open Redirect in showdoc | 中危 | Packagistshowdoc/showdoc | 已审查 | 2021-12-16 23:31 | 2021-12-07 05:57 |
| GHSA-HX6G-Q9V2-XH7V CVE-2021-3980 | Information exposure in elgg | 高危 | Packagistelgg/elgg | 已审查 | 2021-12-16 23:30 | 2021-12-07 06:01 |
| GHSA-74R6-GRJ9-8RQ6 | Duplicate Advisory: Remote Code Execution in AjaxNetProfessional 已撤回 | 严重 | NuGetAjaxNetProfessional | 已审查 | 2021-12-16 23:27 | 2026-02-04 01:39 |
| GHSA-2WR2-8QJQ-GH55 CVE-2021-23264 | Exposure of Resource to Wrong Sphere in org.craftercms:crafter-search | 严重 | Mavenorg.craftercms:crafter-search | 已审查 | 2021-12-16 23:27 | 2021-12-07 05:35 |
| GHSA-XQ58-69H2-765M CVE-2021-44227 | Cross Site Request Forgery in mailman | 高危 | PyPImailman | 已审查 | 2021-12-16 23:27 | 2021-12-07 05:52 |
| GHSA-X949-7CM6-FM6P CVE-2021-23639 | Code Injection in md-to-pdf. | 严重 | npmmd-to-pdf | 已审查 | 2021-12-16 22:34 | 2021-12-15 23:22 |
| GHSA-J28Q-P8WW-CP87 CVE-2021-23700 | Prototype Pollution in merge-deep2. | 中危 | npmmerge-deep2 | 已审查 | 2021-12-16 22:33 | 2021-12-15 23:23 |
| GHSA-9VWF-54M9-GC4F CVE-2021-4089 | snipe-it is vulnerable to Improper Access Control | 中危 | Packagistsnipe/snipe-it | 已审查 | 2021-12-16 22:32 | 2022-08-12 03:17 |
| GHSA-VXR4-RXW7-G7V6 CVE-2021-23561 | Prototype Pollution in comb | 中危 | npmcomb | 已审查 | 2021-12-16 22:30 | 2023-09-12 00:21 |
| GHSA-7RPJ-HG47-CX62 CVE-2021-23463 | Improper Restriction of XML External Entity Reference in com.h2database:h2. | 高危 | Mavencom.h2database:h2 | 已审查 | 2021-12-16 22:29 | 2023-03-22 00:18 |
| GHSA-WJPC-CGVW-XX23 CVE-2021-23663 | Prototype Pollution in sey | 中危 | npmsey | 已审查 | 2021-12-16 22:29 | 2023-09-09 05:04 |
| GHSA-8W3X-R6X7-C5R5 CVE-2021-4084 | Cross-site Scripting in pimcore | 中危 | Packagistpimcore/pimcore | 已审查 | 2021-12-16 22:28 | 2021-12-14 22:44 |
| GHSA-2V2V-FX7R-F2FH CVE-2021-4082 | pimcore is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistpimcore/pimcore | 已审查 | 2021-12-16 22:28 | 2021-12-14 22:45 |
| GHSA-3P85-P4QG-HCRP CVE-2021-4081 | pimcore is vulnerable to Cross-site Scripting | 中危 | Packagistpimcore/pimcore | 已审查 | 2021-12-16 22:27 | 2021-12-14 23:06 |
| GHSA-8QV8-FQ5W-P966 CVE-2021-4097 | phpservermon is vulnerable to CRLF Injection | 中危 | Packagistphpservermon/phpservermon | 已审查 | 2021-12-16 22:26 | 2021-12-16 22:09 |
| GHSA-V4CR-M5F8-GXW8 CVE-2021-4092 | yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistyetiforce/yetiforce-crm | 已审查 | 2021-12-16 22:14 | 2021-12-15 23:20 |
| GHSA-RXCH-GP62-574W CVE-2021-4108 | snipe-it is vulnerable to Cross-site Scripting | 中危 | Packagistsnipe/snipe-it | 已审查 | 2021-12-16 22:13 | 2022-01-05 03:01 |