检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-93G4-3PHC-G4XW CVE-2021-27644 | SQL injection in Apache DolphinScheduler | 高危 | Mavenorg.apache.dolphinscheduler:dolphinscheduler-server | 已审查 | 2021-11-04 01:30 | 2021-11-03 22:48 |
| GHSA-HF9P-9R39-R2H3 CVE-2020-11476 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistconcrete5/concrete5 |
| 已审查 |
| 2021-11-04 01:29 |
| 2021-11-03 02:39 |
| GHSA-R8HM-W5F7-WJ39 CVE-2024-21910 | Cross-site scripting vulnerability in TinyMCE plugins | 中危 | npmdjango-tinymce+3 | 已审查 | 2021-11-02 23:42 | 2024-01-04 06:33 |
| GHSA-4QWQ-Q4PR-RR7R CVE-2020-36378 | Vulnerability in packageCmd function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 23:42 | 2022-05-04 11:45 |
| GHSA-9CQ3-FJ2H-GGJ5 CVE-2020-36379 | Vulnerability in remove function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 23:42 | 2022-05-04 09:52 |
| GHSA-R496-7HGP-53WF CVE-2020-36377 | Vulnerability in dump function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 23:42 | 2022-05-04 11:45 |
| GHSA-4G7X-7VGQ-3J28 CVE-2020-36376 | Vulnerability in list function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 23:42 | 2022-05-04 11:46 |
| GHSA-V899-28G4-QMH8 CVE-2020-26705 | XML External Entity vulnerability in Easy-XML | 高危 | PyPIeasy-xml | 已审查 | 2021-11-02 03:19 | 2024-11-19 00:26 |
| GHSA-VHFP-9WVJ-GWVG CVE-2020-25911 | XML External Entity vulnerability in MODX CMS | 严重 | Packagistmodx/revolution | 已审查 | 2021-11-02 03:19 | 2021-11-03 22:51 |
| GHSA-7FW7-GH23-F832 CVE-2020-36381 | Vulnerability in singleCrunch function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 03:19 | 2022-05-04 11:47 |
| GHSA-M7P2-GHFH-PJVX CVE-2020-36380 | Vulnerability in crunch function leads to arbitrary code execution via filePath parameters | 严重 | npmaaptjs | 已审查 | 2021-11-02 03:18 | 2022-05-04 11:44 |
| GHSA-CF2J-VF36-C6W8 CVE-2021-41189 | Communities and collections administrators can escalate their privilege up to system administrator | 高危 | Mavenorg.dspace:dspace-api | 已审查 | 2021-11-02 03:18 | 2021-10-30 01:26 |
| GHSA-5JXC-HMQF-3F73 CVE-2021-3904 | Cross-Site Scripting in grav | 中危 | Packagistgetgrav/grav | 已审查 | 2021-11-02 03:17 | 2021-11-01 22:06 |
| GHSA-HWHF-64MH-R662 CVE-2021-41186 | ReDoS vulnerability in parser_apache2 | 中危 | RubyGemsfluentd | 已审查 | 2021-11-02 03:16 | 2021-11-05 01:05 |
| GHSA-F5F7-6478-QM6P CVE-2021-25741 | Files or Directories Accessible to External Parties in kubernetes | 高危 | Gok8s.io/kubernetes | 已审查 | 2021-11-02 01:32 | 2021-11-02 01:26 |
| GHSA-PFJ7-W373-GQCH CVE-2021-3900 | Cross-Site Request Forgery in firefly-iii | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-10-29 07:14 | 2021-10-29 21:49 |
| GHSA-RQGP-CCPH-5W65 CVE-2021-3901 | Cross-Site Request Forgery in firefly-iii | 低危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-10-29 07:14 | 2021-11-03 02:42 |
| GHSA-97X5-CC53-CV4V CVE-2020-22864 | Cross site scripting in froala-editor | 中危 | npmfroala-editor | 已审查 | 2021-10-29 07:14 | 2021-10-29 01:21 |
| GHSA-5XVC-VGMP-JGC3 CVE-2021-41194 | Improper Access Control in jupyterhub-firstuseauthenticator | 严重 | PyPIjupyterhub-firstuseauthenticator | 已审查 | 2021-10-29 07:13 | 2024-09-25 05:11 |
| GHSA-M836-GXWQ-J2PM | Improper Access Control in github.com/treeverse/lakefs | 中危 | Gogithub.com/treeverse/lakefs | 已审查 | 2021-10-29 00:27 | 2021-10-28 02:58 |
| GHSA-J8FQ-86C5-5V2R | Duplicate Advisory: Remote code execution in dask 已撤回 | 严重 | PyPIdask | 已审查 | 2021-10-28 02:53 | 2026-02-04 01:37 |
| GHSA-4P3X-8QW9-24W9 CVE-2021-41188 | Authenticated Stored XSS in shopware/shopware | 中危 | Packagistshopware/shopware | 已审查 | 2021-10-28 02:53 | 2021-10-27 01:56 |
| GHSA-JVJP-VH27-R9H5 CVE-2021-25977 | Cross-site Scripting in PiranhaCMS | 中危 | NuGetPiranha | 已审查 | 2021-10-28 02:53 | 2021-10-28 01:07 |
| GHSA-W729-7633-2FW5 CVE-2021-40865 | Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm | 严重 | Mavenorg.apache.storm:storm | 已审查 | 2021-10-28 02:52 | 2021-10-29 21:51 |
| GHSA-6768-MCJC-8223 CVE-2021-38294 | Command injection leading to Remote Code Execution in Apache Storm | 严重 | Mavenorg.apache.storm:storm | 已审查 | 2021-10-28 02:51 | 2022-10-19 23:36 |