检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q854-J362-CFQ9 CVE-2020-23849 | Cross-site Scripting in jsoneditor | 中危 | npmjsoneditor | 已审查 | 2021-10-13 00:22 | 2021-10-09 05:54 |
| GHSA-5F38-9JW2-6R6H CVE-2021-23447 | Cross-site Scripting in teddy |
当前筛选结果 366,391 条 · 时间按北京时间显示
npmteddy |
| 已审查 |
| 2021-10-13 00:22 |
| 2022-05-04 11:42 |
| GHSA-3R3G-G73X-G593 CVE-2021-20319 | coreos-installer improperly verifies GPG signature when decompressing gzipped artifact | 高危 | crates.iocoreos-installer | 已审查 | 2021-10-13 00:06 | 2025-12-23 00:27 |
| GHSA-QH54-9VC5-M9FG | MD5 hash support in github.com/foxcpp/maddy | 低危 | Gogithub.com/foxcpp/maddy | 已审查 | 2021-10-13 00:06 | 2021-10-12 05:16 |
| GHSA-Q324-Q795-2Q5P | Path traversal when using `preview-docs` when working dir contains files with question mark `?` in name | 低危 | npm@redocly/openapi-cli | 已审查 | 2021-10-13 00:05 | 2021-10-12 02:40 |
| GHSA-PGH6-M65R-2RHQ CVE-2021-22964 | DOS and Open Redirect with user input | 高危 | npmfastify-static | 已审查 | 2021-10-13 00:04 | 2021-10-21 22:57 |
| GHSA-PGJJ-866W-FC5C CVE-2021-21278 | Risk of code injection | 高危 | npmrsshub | 已审查 | 2021-10-13 00:03 | 2021-10-12 00:14 |
| GHSA-CX2R-MF6X-55RX CVE-2020-5273 | Stored XSS with custom URLs in PrestaShop module ps_linklist | 中危 | Packagistprestashop/ps_linklist | 已审查 | 2021-10-13 00:01 | 2021-10-09 06:31 |
| GHSA-WQGP-VPHW-HPHF CVE-2020-8897 | Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness | 高危 | Mavenaws-encryption-sdk+1 | 已审查 | 2021-10-13 00:01 | 2024-09-05 03:24 |
| GHSA-4VR9-8CJF-VF9C CVE-2020-26281 | Async-h1 request smuggling possible with long unread bodies | 中危 | crates.ioasync-h1 | 已审查 | 2021-10-13 00:00 | 2021-10-09 06:14 |
| GHSA-XV8X-PR4H-73JV CVE-2021-41121 | Memory corruption when returning a literal struct with a private call inside of it | 高危 | PyPIvyper | 已审查 | 2021-10-12 23:59 | 2024-11-19 06:44 |
| GHSA-3F99-HVG4-QJWJ CVE-2021-41117 | Insecure random number generation in keypair | 高危 | npmkeypair | 已审查 | 2021-10-12 01:09 | 2021-10-12 02:36 |
| GHSA-GQHP-5J32-XWMM CVE-2021-22930 | Use After Free in node.js | 严重 | —— | 未审查 | 2021-10-09 05:47 | 2021-11-30 02:26 |
| GHSA-823F-CWM9-4G74 CVE-2021-41124 | Splash authentication credentials potentially leaked to target websites | 高危 | PyPIscrapy-splash | 已审查 | 2021-10-07 01:49 | 2024-10-27 06:52 |
| GHSA-25FX-MXC2-76G7 CVE-2021-41120 | Sylius PayPal Plugin allows unauthorized access to Credit card form, exposing payer name and not requiring 3DS | 高危 | Packagistsylius/paypal-plugin | 已审查 | 2021-10-07 01:49 | 2022-08-16 04:11 |
| GHSA-C7PR-343R-5C46 CVE-2021-41122 | missing clamps for decimal args in external functions | 中危 | PyPIvyper | 已审查 | 2021-10-07 01:48 | 2024-11-19 06:44 |
| GHSA-V6W3-2PRQ-H95F CVE-2021-28170 | Improper Input Validation in Jakarta Expression Language | 中危 | Mavencom.sun.el:el-ri+2 | 已审查 | 2021-10-07 01:48 | 2025-07-02 00:13 |
| GHSA-VMFH-C547-V45H CVE-2021-33575 | Remote code execution in ruby-jss | 严重 | RubyGemsruby-jss | 已审查 | 2021-10-07 01:48 | 2021-10-06 21:46 |
| GHSA-37HX-4MCQ-WC3H CVE-2021-28128 | Weak Password Recovery Mechanism for Forgotten Password in Strapi | 高危 | npmstrapi | 已审查 | 2021-10-07 01:48 | 2021-10-06 22:09 |
| GHSA-PFWG-RXF4-97C3 CVE-2021-28125 | Open Redirect in Apache Superset | 中危 | PyPIapache-superset+1 | 已审查 | 2021-10-07 01:47 | 2022-06-02 06:01 |
| GHSA-M2R3-8492-VX59 CVE-2021-23372 | Denial of Service (DoS) in mongo-express | 中危 | npmmongo-express | 已审查 | 2021-10-07 01:47 | 2021-10-06 23:13 |
| GHSA-M6M5-PP4G-FCC8 | S3 storage write is not aborted on errors leading to unbounded memory usage | 高危 | Gogithub.com/foxcpp/maddy | 已审查 | 2021-10-07 01:47 | 2021-10-07 00:48 |
| GHSA-GRH7-935J-HG6W CVE-2021-30151 | Cross-site Scripting in Sidekiq | 中危 | RubyGemssidekiq | 已审查 | 2021-10-07 01:47 | 2023-01-24 23:03 |
| GHSA-CQ6W-W5RJ-P9X8 CVE-2021-30109 | Cross-site Scripting in Froala Editor | 中危 | npmfroala-editor | 已审查 | 2021-10-07 01:47 | 2021-10-07 00:55 |
| GHSA-M6J4-8R7P-WPP3 CVE-2021-21389 | BuddyPress privilege escalation via REST API | 高危 | Packagistbuddypress/buddypress | 已审查 | 2021-10-07 01:46 | 2021-10-07 00:57 |