检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-R6G8-JMJ9-G945 CVE-2021-3734 | Improper Restriction of Rendered UI Layers or Frames in yourls | 中危 | Packagistyourls/yourls | 已审查 | 2021-08-31 00:22 | 2021-08-27 20:54 |
| GHSA-HGJR-632X-QPP3 CVE-2021-39136 | Cross-site scripting vulnerability in file upload |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistbaserproject/basercms |
| 已审查 |
| 2021-08-31 00:18 |
| 2021-08-26 23:08 |
| GHSA-MQ5P-2MCR-M52J CVE-2021-39160 | Code injection in nbgitpuller | 高危 | PyPInbgitpuller | 已审查 | 2021-08-31 00:17 | 2024-10-04 05:28 |
| GHSA-9JJR-QQFP-PPWX CVE-2021-39159 | remote code execution via git repo provider | 严重 | PyPIbinderhub | 已审查 | 2021-08-31 00:16 | 2024-09-14 02:05 |
| GHSA-HW7R-QRHP-5PFF | Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20 | 中危 | Mavencom.vaadin:vaadin-bom | 已审查 | 2021-08-31 00:16 | 2021-08-25 23:42 |
| GHSA-QCC4-3RXF-GF4M CVE-2021-33605 | Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20 | 中危 | Mavencom.vaadin:vaadin-checkbox-flow | 已审查 | 2021-08-31 00:16 | 2021-09-04 04:35 |
| GHSA-HQXW-MM44-GC4R CVE-2021-39156 | Istio Fragments in Path May Lead to Authorization Policy Bypass | 高危 | Goistio.io/istio | 已审查 | 2021-08-31 00:16 | 2022-08-16 04:04 |
| GHSA-7774-7VR3-CC8J CVE-2021-39155 | Authorization Policy Bypass Due to Case Insensitive Host Comparison | 高危 | Goistio.io/istio | 已审查 | 2021-08-31 00:15 | 2021-12-13 21:09 |
| GHSA-9856-9GG9-QCMQ CVE-2021-39137 | Ethereum Contains Consensus Flaw During Block Processing | 中危 | Gogithub.com/ethereum/go-ethereum | 已审查 | 2021-08-31 00:15 | 2025-01-30 22:37 |
| GHSA-54GP-QFF8-946C CVE-2021-37709 | Insecure direct object reference of log files of the Import/Export feature | 中危 | Packagistshopware/core+1 | 已审查 | 2021-08-31 00:14 | 2021-08-27 03:36 |
| GHSA-XH55-2FQP-P775 CVE-2021-37708 | Command injection in mail agent settings | 高危 | Packagistshopware/core+1 | 已审查 | 2021-08-31 00:14 | 2021-08-27 03:40 |
| GHSA-9F8F-574Q-8JMF CVE-2021-37707 | Manipulation of product reviews via API | 中危 | Packagistshopware/core+1 | 已审查 | 2021-08-31 00:14 | 2021-08-27 03:40 |
| GHSA-H76R-VGF3-J6W5 CVE-2021-29487 | October CMS auth bypass and account takeover | 高危 | Packagistoctober/system | 已审查 | 2021-08-31 00:13 | 2022-08-11 08:18 |
| GHSA-CVH5-P6R6-G2QC CVE-2021-37704 | Exposed phpinfo() leadked via documentation files | 中危 | Packagistphpfastcache/phpfastcache | 已审查 | 2021-08-31 00:13 | 2021-08-27 04:11 |
| GHSA-PP2H-95HM-HV9R CVE-2021-37702 | Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore | 中危 | Packagistpimcore/pimcore | 已审查 | 2021-08-31 00:13 | 2021-08-27 20:49 |
| GHSA-MXR5-MC97-63RC CVE-2021-32648 | Account Takeover in Octobercms | 高危 | Packagistoctober/system | 已审查 | 2021-08-31 00:13 | 2025-10-23 03:06 |
| GHSA-79MG-4W23-4FQC CVE-2021-39165 | Unauthenticated SQL Injection in Cachet | 高危 | Packagistcachethq/cachet | 已审查 | 2021-08-31 00:12 | 2021-08-27 20:54 |
| GHSA-VRW4-W73R-6MM8 CVE-2021-39168 | TimelockController vulnerability in OpenZeppelin Contracts | 严重 | npm@openzeppelin/contracts-upgradeable | 已审查 | 2021-08-31 00:12 | 2021-09-14 04:30 |
| GHSA-FG47-3C2X-M2WR CVE-2021-39167 | TimelockController vulnerability in OpenZeppelin Contracts | 严重 | npm@openzeppelin/contracts | 已审查 | 2021-08-31 00:12 | 2021-09-14 04:30 |
| GHSA-5379-R78W-42H2 CVE-2021-39171 | Unlimited transforms allowed for signed nodes | 中危 | npmpassport-saml | 已审查 | 2021-08-31 00:11 | 2024-02-10 08:55 |
| GHSA-88F9-7XXH-C688 CVE-2021-39174 | Cachet configuration leak | 高危 | Packagistcachethq/cachet | 已审查 | 2021-08-31 00:11 | 2022-08-17 02:38 |
| GHSA-R67M-M8C7-JP83 CVE-2021-39173 | Cachet vulnerable to forced reinstall | 高危 | Packagistcachethq/cachet | 已审查 | 2021-08-31 00:11 | 2022-08-17 02:40 |
| GHSA-9JXW-CFRH-JXQ6 CVE-2021-39172 | Cachet vulnerable to new line injection during configuration edition | 高危 | Packagistcachethq/cachet | 已审查 | 2021-08-31 00:11 | 2022-08-11 08:16 |
| GHSA-2RQW-V265-JF8C CVE-2021-22942 | Open Redirect in ActionPack | 中危 | RubyGemsactionpack | 已审查 | 2021-08-27 04:36 | 2024-02-03 00:47 |
| GHSA-HPQH-2WQX-7QP5 CVE-2021-32629 | Memory access due to code generation flaw in Cranelift module | 高危 | crates.iocranelift-codegen+1 | 已审查 | 2021-08-26 05:01 | 2024-11-20 03:18 |