检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W65J-G6C7-G3M4 | Multiple memory safety issues in actix-web | 中危 | crates.ioactix-web | 已审查 | 2021-08-26 04:42 | 2026-06-09 18:46 |
| GHSA-XP5Q-77MH-6HM2 CVE-2021-3728 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
当前筛选结果 35,190 条 · 时间按北京时间显示
Packagistgrumpydictator/firefly-iii |
| 已审查 |
| 2021-08-25 22:50 |
| 2021-08-25 04:02 |
| GHSA-C676-MCW3-QG55 CVE-2021-3730 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-08-25 22:50 | 2021-08-27 20:48 |
| GHSA-GP6W-CCQV-P7QR CVE-2021-3729 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-08-25 22:49 | 2021-08-25 04:06 |
| GHSA-X2XG-6WCJ-6XF9 CVE-2020-36474 | SafeCurl before 0.9.2 has a DNS rebinding vulnerability. | 严重 | Packagistvanilla/safecurl | 已审查 | 2021-08-25 22:49 | 2021-08-25 04:08 |
| GHSA-64XX-CQ4Q-MF44 CVE-2021-39139 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:48 | 2022-02-09 05:01 |
| GHSA-6WF9-JMG9-VXCC CVE-2021-39140 | XStream can cause a Denial of Service | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:48 | 2022-02-09 04:59 |
| GHSA-G5W6-MRJ7-75H2 CVE-2021-39141 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:48 | 2022-02-09 04:58 |
| GHSA-J9H8-PHRW-H4FH CVE-2021-39144 | XStream is vulnerable to a Remote Command Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:48 | 2025-10-23 03:07 |
| GHSA-8JRJ-525P-826V CVE-2021-39145 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:48 | 2022-07-30 02:10 |
| GHSA-P8PQ-R894-FM8F CVE-2021-39146 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 05:00 |
| GHSA-H7V4-7XG3-HXCC CVE-2021-39147 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 04:58 |
| GHSA-QRX8-8545-4WG2 CVE-2021-39148 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 04:59 |
| GHSA-3CCQ-5VW3-2P6X CVE-2021-39149 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 04:44 |
| GHSA-CXFM-5M4G-X7XP CVE-2021-39150 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 04:43 |
| GHSA-HPH2-M3G5-XXV4 CVE-2021-39151 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:47 | 2022-02-09 04:44 |
| GHSA-XW4P-CRPJ-VJX2 CVE-2021-39152 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:46 | 2022-02-09 04:43 |
| GHSA-2Q8X-2P7F-574V CVE-2021-39153 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:46 | 2022-02-09 04:43 |
| GHSA-6W62-HX7R-MW68 CVE-2021-39154 | XStream is vulnerable to an Arbitrary Code Execution attack | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-08-25 22:46 | 2022-02-09 04:43 |
| GHSA-XJ6R-2JPM-QVXP CVE-2021-37694 | Code injection issue for java-spring-cloud-stream-template | 高危 | npm@asyncapi/java-spring-cloud-stream-template | 已审查 | 2021-08-25 22:45 | 2021-08-25 02:50 |
| GHSA-Q7CG-43MG-QP69 CVE-2021-34532 | ASP.NET Core Information Disclosure Vulnerability | 中危 | NuGetMicrosoft.AspNetCore.Authentication.JwtBearer | 已审查 | 2021-08-25 22:45 | 2026-08-12 01:22 |
| GHSA-HR3H-X6GQ-RQCP CVE-2021-35955 | Cross site scripting via HTML attributes in the back end | 中危 | Packagistcontao/contao+1 | 已审查 | 2021-08-25 22:45 | 2025-04-17 20:45 |
| GHSA-JQFH-8HW5-FQJR CVE-2021-39157 | Improper Handling of Exceptional Conditions in detect-character-encoding | 高危 | npmdetect-character-encoding | 已审查 | 2021-08-25 22:44 | 2021-10-21 22:15 |
| GHSA-CGFM-62J4-V4RF CVE-2021-37635 | Heap out of bounds access in sparse reduction operations | 高危 | PyPItensorflow+2 | 已审查 | 2021-08-25 22:44 | 2024-11-14 00:36 |
| GHSA-HP4C-X6R7-6555 CVE-2021-37636 | Floating point exception in `SparseDenseCwiseDiv` | 中危 | PyPItensorflow+2 | 已审查 | 2021-08-25 22:44 | 2024-11-14 00:35 |