检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8XJQ-8FCG-G5HW CVE-2021-25290 | Out-of-bounds Write in Pillow | 高危 | PyPIpillow | 已审查 | 2021-03-30 00:35 | 2024-10-08 21:11 |
| GHSA-P43W-G3C5-G5MQ CVE-2021-25293 | Out of bounds read in Pillow |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIPillow |
| 已审查 |
| 2021-03-30 00:35 |
| 2024-10-10 04:12 |
| GHSA-57H3-9RGR-C24M CVE-2021-25289 | Out of bounds write in Pillow | 严重 | PyPIpillow | 已审查 | 2021-03-30 00:35 | 2024-10-08 21:11 |
| GHSA-PQ64-V7F5-GQH8 CVE-2021-27291 | Pygments vulnerable to Regular Expression Denial of Service (ReDoS) | 高危 | PyPIPygments | 已审查 | 2021-03-30 00:33 | 2024-10-15 00:10 |
| GHSA-MPVW-25MG-59VX CVE-2020-28463 | Server-side Request Forgery (SSRF) via img tags in reportlab | 高危 | PyPIreportlab | 已审查 | 2021-03-30 00:32 | 2024-10-27 02:34 |
| GHSA-52P9-V744-MWJJ CVE-2021-28834 | Remote code execution in Kramdown | 高危 | RubyGemskramdown | 已审查 | 2021-03-30 00:30 | 2021-04-01 04:25 |
| GHSA-P6P8-Q4PJ-F74M CVE-2020-24392 | Improper Certificate Validation in twitter-stream | 中危 | RubyGemstwitter-stream | 已审查 | 2021-03-30 00:28 | 2021-03-20 03:21 |
| GHSA-C4W7-XM78-47VH CVE-2020-7774 | Prototype Pollution in y18n | 高危 | npmy18n | 已审查 | 2021-03-30 00:05 | 2023-09-08 04:22 |
| GHSA-C5F8-35QR-Q4FM CVE-2021-21333 | HTML injection in email and account expiry notifications | 中危 | PyPImatrix-synapse | 已审查 | 2021-03-27 03:53 | 2024-10-01 04:35 |
| GHSA-246W-56M2-5899 CVE-2021-21332 | Cross-site scripting (XSS) vulnerability in the password reset endpoint | 中危 | PyPImatrix-synapse | 已审查 | 2021-03-27 03:52 | 2024-10-01 04:30 |
| GHSA-2H3H-VW8R-82RP CVE-2021-27884 | Weak JSON Web Token in yapi-vendor | 中危 | npmyapi-vendor | 已审查 | 2021-03-27 00:49 | 2021-07-22 23:58 |
| GHSA-8Q59-Q68H-6HV4 CVE-2020-14343 | Improper Input Validation in PyYAML | 严重 | PyPIPyYAML | 已审查 | 2021-03-26 05:26 | 2024-10-26 05:31 |
| GHSA-8MRF-64FW-2X75 CVE-2020-8298 | Command injection in fs-path | 严重 | npmfs-path | 已审查 | 2021-03-26 05:06 | 2021-03-26 05:05 |
| GHSA-5MG8-W23W-74H3 CVE-2020-8908 | Information Disclosure in Guava | 低危 | Mavencom.google.guava:guava | 已审查 | 2021-03-26 01:04 | 2026-02-24 06:45 |
| GHSA-537H-RV9Q-VVPH CVE-2020-13757 | Python-RSA decryption of ciphertext leads to DoS | 高危 | PyPIrsa | 已审查 | 2021-03-25 02:24 | 2024-10-22 05:54 |
| GHSA-VGWR-773Q-7J3C CVE-2021-26028 | Path Traversal within joomla/archive zip class | 中危 | Packagistjoomla/archive | 已审查 | 2021-03-25 01:58 | 2021-03-25 01:57 |
| GHSA-XGPF-P52J-PF7M CVE-2021-27938 | XSS in CreateQueuedJobTask | 中危 | Packagistsymbiote/silverstripe-queuedjobs | 已审查 | 2021-03-25 01:42 | 2021-03-25 01:41 |
| GHSA-79RG-7MV3-JRR5 CVE-2021-21380 | Rating Script Service expose XWiki to SQL injection | 高危 | Mavenorg.xwiki.platform:xwiki-platform-ratings-api | 已审查 | 2021-03-24 06:48 | 2021-03-24 06:34 |
| GHSA-V662-XPCC-9XF6 CVE-2021-21379 | It's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macro | 低危 | Mavenorg.xwiki.platform:xwiki-platform-rendering-wikimacro-store | 已审查 | 2021-03-24 06:47 | 2021-03-24 06:24 |
| GHSA-G4RF-PC26-6HMR CVE-2021-21377 | OMERO webclient does not validate URL redirects on login or switching group. | 中危 | PyPIomero-web | 已审查 | 2021-03-23 23:26 | 2024-10-08 20:43 |
| GHSA-GFP2-W5JM-955Q CVE-2021-21376 | OMERO.web exposes some unnecessary session information in the page | 高危 | PyPIomero-web | 已审查 | 2021-03-23 23:26 | 2024-10-08 05:25 |
| GHSA-X7HC-X7FM-F7QH CVE-2021-21370 | Cross-Site Scripting in Content Preview (CType menu) | 中危 | Packagisttypo3/cms+2 | 已审查 | 2021-03-23 09:54 | 2024-02-03 00:44 |
| GHSA-4P9G-QGX9-397P CVE-2021-21359 | Denial of Service in Page Error Handling | 中危 | Packagisttypo3/cms+1 | 已审查 | 2021-03-23 09:54 | 2024-02-08 02:50 |
| GHSA-X79J-WGQV-G8H2 CVE-2021-21358 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form | 中危 | Packagisttypo3/cms+2 | 已审查 | 2021-03-23 09:54 | 2021-03-30 02:02 |
| GHSA-3VG7-JW9M-PC3F CVE-2021-21357 | Broken Access Control in Form Framework | 高危 | Packagisttypo3/cms+2 | 已审查 | 2021-03-23 09:53 | 2021-03-30 02:01 |