检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-C7PR-343R-5C46 CVE-2021-41122 | missing clamps for decimal args in external functions | 中危 | PyPIvyper | 已审查 | 2021-10-07 01:48 | 2024-11-19 06:44 |
| GHSA-V6W3-2PRQ-H95F CVE-2021-28170 | Improper Input Validation in Jakarta Expression Language |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavencom.sun.el:el-ri+2 |
| 已审查 |
| 2021-10-07 01:48 |
| 2025-07-02 00:13 |
| GHSA-VMFH-C547-V45H CVE-2021-33575 | Remote code execution in ruby-jss | 严重 | RubyGemsruby-jss | 已审查 | 2021-10-07 01:48 | 2021-10-06 21:46 |
| GHSA-37HX-4MCQ-WC3H CVE-2021-28128 | Weak Password Recovery Mechanism for Forgotten Password in Strapi | 高危 | npmstrapi | 已审查 | 2021-10-07 01:48 | 2021-10-06 22:09 |
| GHSA-PFWG-RXF4-97C3 CVE-2021-28125 | Open Redirect in Apache Superset | 中危 | PyPIapache-superset+1 | 已审查 | 2021-10-07 01:47 | 2022-06-02 06:01 |
| GHSA-M2R3-8492-VX59 CVE-2021-23372 | Denial of Service (DoS) in mongo-express | 中危 | npmmongo-express | 已审查 | 2021-10-07 01:47 | 2021-10-06 23:13 |
| GHSA-M6M5-PP4G-FCC8 | S3 storage write is not aborted on errors leading to unbounded memory usage | 高危 | Gogithub.com/foxcpp/maddy | 已审查 | 2021-10-07 01:47 | 2021-10-07 00:48 |
| GHSA-GRH7-935J-HG6W CVE-2021-30151 | Cross-site Scripting in Sidekiq | 中危 | RubyGemssidekiq | 已审查 | 2021-10-07 01:47 | 2023-01-24 23:03 |
| GHSA-CQ6W-W5RJ-P9X8 CVE-2021-30109 | Cross-site Scripting in Froala Editor | 中危 | npmfroala-editor | 已审查 | 2021-10-07 01:47 | 2021-10-07 00:55 |
| GHSA-M6J4-8R7P-WPP3 CVE-2021-21389 | BuddyPress privilege escalation via REST API | 高危 | Packagistbuddypress/buddypress | 已审查 | 2021-10-07 01:46 | 2021-10-07 00:57 |
| GHSA-6GJF-7W99-J7X7 CVE-2021-41126 | Deleted Admin Can Sign In to Admin Interface | 高危 | Packagistoctober/october+1 | 已审查 | 2021-10-07 01:46 | 2022-10-14 02:02 |
| GHSA-JWQP-28GF-P498 CVE-2021-41125 | Scrapy HTTP authentication credentials potentially leaked to target websites | 中危 | PyPIScrapy | 已审查 | 2021-10-07 01:46 | 2024-10-27 06:53 |
| GHSA-MCWM-2WMC-6HV4 CVE-2021-31957 | ASP.NET Core Denial of Service Vulnerability 已撤回 | 高危 | NuGetMicrosoft.NETCore.App.Ref | 已审查 | 2021-10-06 08:23 | 2021-10-06 08:23 |
| GHSA-P6VG-P826-QP3V CVE-2021-22963 | URL Redirection to Untrusted Site ('Open Redirect') in fastify-static | 中危 | npmfastify-static | 已审查 | 2021-10-06 04:24 | 2021-10-21 23:01 |
| GHSA-7534-MM45-C74V CVE-2021-34552 | Buffer Overflow in Pillow | 严重 | PyPIpillow | 已审查 | 2021-10-06 04:24 | 2024-10-10 05:03 |
| GHSA-69J6-29VR-P3J9 CVE-2021-39226 | Authentication bypass for viewing and deletions of snapshots | 高危 | Gogithub.com/grafana/grafana | 已审查 | 2021-10-06 04:24 | 2025-10-23 03:08 |
| GHSA-657M-V5VM-F6RW CVE-2021-41113 | Cross-Site-Request-Forgery in Backend | 高危 | Packagisttypo3/cms+1 | 已审查 | 2021-10-06 04:23 | 2024-02-05 19:18 |
| GHSA-M2JH-FXW4-GPHM CVE-2021-41114 | HTTP Host Header Injection | 中危 | Packagisttypo3/cms+1 | 已审查 | 2021-10-06 04:23 | 2021-10-06 02:47 |
| GHSA-FRQG-7G38-6GCF CVE-2021-41116 | Improper escaping of command arguments on Windows leading to command injection | 高危 | Packagistcomposer/composer | 已审查 | 2021-10-06 04:23 | 2021-10-12 02:39 |
| GHSA-J28R-J54M-GPC4 CVE-2021-22557 | Code Injection in SLO Generator | 中危 | PyPIslo-generator | 已审查 | 2021-10-06 01:53 | 2024-10-23 00:34 |
| GHSA-CR3F-R24J-3CHW CVE-2021-40325 | Cobbler before 3.3.0 allows authorization bypass for modification of settings. | 高危 | PyPIcobbler | 已审查 | 2021-10-06 01:53 | 2024-09-14 01:50 |
| GHSA-CPQF-3C3R-C9G2 CVE-2021-40323 | Cobbler before 3.3.0 allows log poisoning | 高危 | PyPIcobbler | 已审查 | 2021-10-06 01:53 | 2024-09-13 23:11 |
| GHSA-4CFR-GJFX-FJ3X CVE-2021-40324 | Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. | 高危 | PyPIcobbler | 已审查 | 2021-10-06 01:53 | 2024-09-14 01:50 |
| GHSA-C2H3-6MXW-7MVQ CVE-2021-41103 | Insufficiently restricted permissions on plugin directories | 中危 | Gogithub.com/containerd/containerd | 已审查 | 2021-10-05 04:14 | 2021-10-16 01:31 |
| GHSA-XPV2-8PPJ-79HH CVE-2021-41862 | Expression injection in AviatorScript | 严重 | Mavencom.googlecode.aviator:aviator | 已审查 | 2021-10-05 04:14 | 2024-02-21 04:07 |