检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-36MJ-6R7R-MQHF | User can obtain JWT token even if account is disabled | 高危 | Packagistezsystems/ezplatform-rest | 已审查 | 2021-09-30 01:09 | 2021-09-29 05:21 |
| GHSA-48MJ-P7X2-5JFM CVE-2021-41104 | Basic auth bypass in esphome |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIesphome |
| 已审查 |
| 2021-09-30 01:09 |
| 2024-09-21 01:35 |
| GHSA-F263-C949-W85G CVE-2020-7692 | Improper Authorization in Google OAuth Client | 高危 | Mavencom.google.oauth-client:google-oauth-client | 已审查 | 2021-09-29 00:16 | 2021-09-29 00:17 |
| GHSA-G95P-88P4-76CM CVE-2021-28378 | Cross-site Scripting in Gitea | 中危 | Gocode.gitea.io/gitea | 已审查 | 2021-09-28 04:17 | 2021-09-28 03:23 |
| GHSA-9P5G-VG43-MJ5R CVE-2021-36749 | Druid ingestion system Authenticated users can read data from other sources than intended | 中危 | Mavenorg.apache.druid:druid-core | 已审查 | 2021-09-28 04:13 | 2023-09-26 21:13 |
| GHSA-2RR5-8Q37-2W7H CVE-2021-41098 | Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby | 高危 | RubyGemsnokogiri | 已审查 | 2021-09-28 04:12 | 2021-09-29 02:46 |
| GHSA-3C9C-2P65-QVWV CVE-2021-41097 | Prototype pollution in aurelia-path | 严重 | npmaurelia-path | 已审查 | 2021-09-28 04:12 | 2022-05-27 03:50 |
| GHSA-4FR2-J4G9-MPPF CVE-2020-28271 | Prototype Pollution in deephas | 严重 | npmdeephas | 已审查 | 2021-09-24 23:42 | 2023-09-08 06:37 |
| GHSA-3J6G-HXX5-3Q26 CVE-2021-38153 | Observable Discrepancy in Apache Kafka | 中危 | Mavenorg.apache.kafka:kafka_2.11+3 | 已审查 | 2021-09-24 07:18 | 2022-02-09 04:43 |
| GHSA-65P7-PJJ8-GGMR | Member account takeover | 中危 | npmghost | 已审查 | 2021-09-24 07:18 | 2021-09-24 05:14 |
| GHSA-XPWJ-7V8Q-MCGJ CVE-2021-32619 | Deno's static imports inside dynamically imported modules do not adhere to permission checks | 严重 | crates.iodeno | 已审查 | 2021-09-24 07:18 | 2022-08-12 00:54 |
| GHSA-FPV6-F8JW-RC3R CVE-2021-41088 | Elvish vulnerable to remote code execution via the web UI backend | 高危 | Gogithub.com/elves/elvish | 已审查 | 2021-09-24 07:17 | 2022-08-16 04:07 |
| GHSA-HPF7-4C2G-9CHF CVE-2021-31819 | Remote Code Execution in Halibut | 严重 | NuGetHalibut | 已审查 | 2021-09-24 07:17 | 2021-10-01 02:36 |
| GHSA-2PFH-Q76X-GWVM CVE-2021-3583 | Improper Input Validation and Command Injection in Ansible | 高危 | PyPIansible | 已审查 | 2021-09-24 07:16 | 2024-09-07 01:47 |
| GHSA-X38Q-XG2H-RXGX CVE-2020-23478 | Regular Expression Denial of Service in Leo Editor | 高危 | PyPIleo | 已审查 | 2021-09-24 07:14 | 2024-09-28 05:45 |
| GHSA-HV5F-73MR-7VVJ CVE-2021-37860 | Cross-site Scripting in Mattermost | 中危 | Gogithub.com/mattermost/mattermost-server/v5 | 已审查 | 2021-09-24 07:11 | 2021-10-06 21:08 |
| GHSA-QH7X-J4V8-QW5W CVE-2021-41086 | Clipboard-based XSS | 高危 | npmjsuites | 已审查 | 2021-09-23 04:39 | 2021-10-21 22:19 |
| GHSA-VRXP-MG9F-HWF3 CVE-2021-41087 | Improperly Implemented path matching for in-toto-golang | 中危 | Gogithub.com/in-toto/in-toto-golang | 已审查 | 2021-09-23 04:37 | 2021-09-22 05:51 |
| GHSA-55R9-7MF8-M382 CVE-2021-23443 | Cross-site Scripting in edge.js | 中危 | npmedge.js | 已审查 | 2021-09-23 04:36 | 2023-09-12 00:20 |
| GHSA-F3PP-32QC-36W4 CVE-2021-23444 | Prototype Pollution in jointjs | 中危 | npmjointjs | 已审查 | 2021-09-23 04:36 | 2021-09-22 22:30 |
| GHSA-M489-XR35-FJXR | Regular Expression Denial of Service in millisecond | 中危 | npmmillisecond | 已审查 | 2021-09-23 04:35 | 2021-09-23 04:34 |
| GHSA-5VCM-3XC3-W7X3 CVE-2021-41084 | Response Splitting from unsanitized headers | 高危 | Mavenorg.http4s:http4s-client_2.12+8 | 已审查 | 2021-09-23 03:18 | 2025-12-12 05:12 |
| GHSA-4448-RC82-FCR7 CVE-2019-5444 | Path Traversal in serve-here.js | 中危 | npmserve-here.js | 已审查 | 2021-09-23 02:40 | 2022-12-03 12:01 |
| GHSA-8R4G-CG4M-X23C | Denial of Service in node-static | 中危 | npmnode-static | 已审查 | 2021-09-23 02:22 | 2025-10-04 02:27 |
| GHSA-XPFP-F569-Q3P2 CVE-2021-35042 | SQL Injection in Django | 严重 | PyPIDjango | 已审查 | 2021-09-23 01:34 | 2024-09-20 23:12 |