检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-V988-828W-XVF2 | Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui | 高危 | PyPIrucio-webui | 已审查 | 2021-10-23 00:21 | 2021-10-22 05:36 |
| GHSA-H58V-G3Q6-Q9FX CVE-2021-41169 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in sulu/sulu |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Packagistsulu/sulu |
| 已审查 |
| 2021-10-23 00:20 |
| 2021-10-22 05:33 |
| GHSA-VW27-FWJF-5QXM CVE-2021-41146 | Arbitrary command execution on Windows via qutebrowserurl: URL handler | 高危 | PyPIqutebrowser | 已审查 | 2021-10-23 00:20 | 2024-10-17 04:48 |
| GHSA-4365-FHM5-QCRX CVE-2021-41127 | Maliciously Crafted Model Archive Can Lead To Arbitrary File Write | 高危 | PyPIrasa | 已审查 | 2021-10-23 00:19 | 2024-10-17 04:45 |
| GHSA-4MVJ-RQ4V-2FXW CVE-2021-23452 | Prototype Pollution in x-assign | 高危 | npmx-assign | 已审查 | 2021-10-22 01:50 | 2022-12-03 11:56 |
| GHSA-H4M5-QPFP-3MPV CVE-2021-42771 | Directory Traversal in Babel | 高危 | PyPIbabel | 已审查 | 2021-10-22 01:49 | 2024-09-13 04:56 |
| GHSA-3PCQ-34W5-P4G2 CVE-2021-41167 | modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests | 高危 | npmmodern-async | 已审查 | 2021-10-22 01:49 | 2022-08-16 04:14 |
| GHSA-5RG2-6QR5-2XP8 CVE-2021-3863 | Cross-site Scripting in snipe-it | 中危 | Packagistsnipe/snipe-it | 已审查 | 2021-10-22 01:49 | 2021-10-26 04:08 |
| GHSA-C7V4-M269-4995 CVE-2020-25703 | Exposure of Sensitive Information to an Unauthorized Actor in Moodle | 中危 | Packagistmoodle/moodle | 已审查 | 2021-10-22 01:49 | 2021-10-21 00:46 |
| GHSA-G92X-8M54-P89V CVE-2021-3858 | Cross-Site Request Forgery in snipe-it | 中危 | Packagistsnipe/snipe-it | 已审查 | 2021-10-22 01:48 | 2021-10-22 21:56 |
| GHSA-5FVX-5P2R-4MVP CVE-2021-3851 | Open Redirect in firefly-iii | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-10-22 01:48 | 2021-10-26 04:08 |
| GHSA-9G3V-J3CR-6FC6 CVE-2021-3879 | Cross-site Scripting in snipe-it | 中危 | Packagistsnipe/snipe-it | 已审查 | 2021-10-22 01:48 | 2021-10-26 04:08 |
| GHSA-2P6R-37P9-89P2 CVE-2021-41135 | Authz Module Non-Determinism | 中危 | Gogithub.com/cosmos/cosmos-sdk | 已审查 | 2021-10-22 01:46 | 2021-10-21 22:32 |
| GHSA-7M27-3587-83XF CVE-2019-10170 | Privilege Defined With Unsafe Actions in Keycloak | 高危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2021-10-22 01:46 | 2021-10-20 23:06 |
| GHSA-R56Q-VV3C-6G9C CVE-2021-41150 | Improper sanitization of delegated role names | 高危 | crates.iotough | 已审查 | 2021-10-20 04:16 | 2021-10-20 02:06 |
| GHSA-X3R5-Q6MJ-M485 CVE-2021-41149 | Improper sanitization of target names | 高危 | crates.iotough | 已审查 | 2021-10-20 04:16 | 2021-10-20 02:04 |
| GHSA-3W73-FMF3-HG5C CVE-2021-42575 | Policies not properly enforced in OWASP Java HTML Sanitizer | 严重 | Mavencom.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | 已审查 | 2021-10-20 04:15 | 2022-02-24 06:19 |
| GHSA-X95H-979X-CF3J CVE-2021-42576 | Policies not properly enforced in bluemonday | 高危 | Gogithub.com/microcosm-cc/bluemonday+1 | 已审查 | 2021-10-20 04:15 | 2024-10-22 04:18 |
| GHSA-WJW6-2CQR-J4QR CVE-2021-41131 | Client metadata path-traversal | 中危 | PyPItuf | 已审查 | 2021-10-20 04:14 | 2024-11-19 06:45 |
| GHSA-6P52-JR3Q-C94G CVE-2021-41078 | Nameko Arbitrary code execution due to YAML deserialization | 严重 | PyPInameko | 已审查 | 2021-10-19 23:28 | 2024-10-07 22:45 |
| GHSA-RJF2-J2R6-Q8GR CVE-2021-23449 | Prototype Pollution in vm2 | 严重 | npmvm2 | 已审查 | 2021-10-19 23:28 | 2021-10-19 22:18 |
| GHSA-PVH2-PJ76-4M96 CVE-2021-41153 | Specification non-compliance in JUMPI | 高危 | crates.ioevm | 已审查 | 2021-10-19 23:28 | 2021-10-26 04:07 |
| GHSA-PVV8-8FX9-H673 CVE-2021-41151 | Path Traversal in @backstage/plugin-scaffolder-backend | 中危 | npm@backstage/plugin-scaffolder-backend | 已审查 | 2021-10-19 23:28 | 2021-10-26 04:07 |
| GHSA-WV83-JRFH-RP33 CVE-2021-42227 | Cross site scripting in kindeditor | 中危 | npmkindeditor | 已审查 | 2021-10-19 03:44 | 2021-10-21 22:56 |
| GHSA-3WW4-CP53-6G2X CVE-2021-42228 | Cross Site Request Forgery in kindeditor | 高危 | npmkindeditor | 已审查 | 2021-10-19 03:44 | 2021-10-21 22:56 |