检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-MC22-5Q92-8V85 CVE-2021-39228 | Memory Safety Issue when using patch or merge on state and assign the result back to state | 中危 | crates.iotremor-script | 已审查 | 2021-09-21 03:52 | 2021-09-18 01:50 |
| GHSA-WFRJ-QQC2-83CM | Remote command injection when using sendmail email transport |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
npmghost |
| 已审查 |
| 2021-09-21 03:52 |
| 2021-09-18 01:48 |
| GHSA-84P7-FH9C-6G8H | Prototype Pollution in mixme | 高危 | npmmixme | 已审查 | 2021-09-21 03:52 | 2021-09-17 05:30 |
| GHSA-C77F-4RGJ-JFR4 CVE-2021-39391 | Cross-site Scripting in Beego | 中危 | Gogithub.com/beego/beego/v2 | 已审查 | 2021-09-16 04:23 | 2023-12-08 07:44 |
| GHSA-5VP3-V4HC-GX76 CVE-2021-41264 | UUPSUpgradeable vulnerability in @openzeppelin/contracts | 严重 | npm@openzeppelin/contracts+1 | 已审查 | 2021-09-16 04:23 | 2021-11-17 05:44 |
| GHSA-Q4H9-46XG-M3X9 | UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable | 严重 | npm@openzeppelin/contracts-upgradeable | 已审查 | 2021-09-16 04:22 | 2021-09-15 06:17 |
| GHSA-2GHC-6V89-PW9J CVE-2021-3666 | body-parser-xml vulnerable to Prototype Pollution | 高危 | npmbody-parser-xml | 已审查 | 2021-09-15 04:25 | 2022-08-11 07:37 |
| GHSA-2RH5-JVGX-PGW3 | Any storage file can be downloaded from p.sh if full server path is known | 高危 | Packagistezsystems/ezplatform | 已审查 | 2021-09-15 04:25 | 2021-09-15 02:35 |
| GHSA-GQCF-83RQ-GPFR | Any storage file can be downloaded from p.sh if full server path is known | 高危 | Packagistibexa/post-install | 已审查 | 2021-09-15 04:24 | 2021-09-15 02:35 |
| GHSA-23CM-X6J7-6HQ3 CVE-2021-40823 | matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver | 中危 | npmmatrix-js-sdk | 已审查 | 2021-09-15 04:24 | 2023-08-09 03:58 |
| GHSA-CQQH-49MX-FQ63 CVE-2021-3645 | merge vulnerable to Prototype Pollution | 严重 | npm@viking04/merge | 已审查 | 2021-09-14 04:16 | 2022-08-11 07:45 |
| GHSA-4JQC-8M5R-9RPR CVE-2021-23440 | Prototype Pollution in set-value | 高危 | npmset-value+1 | 已审查 | 2021-09-14 04:09 | 2023-11-04 04:24 |
| GHSA-99PX-7724-484V CVE-2021-40146 | Remote Code Execution in Any23 | 严重 | Mavenorg.apache.any23:apache-any23 | 已审查 | 2021-09-14 04:06 | 2021-09-24 21:10 |
| GHSA-838R-HVWH-24H8 CVE-2021-38555 | XML Injection in Any23 | 严重 | Mavenorg.apache.any23:apache-any23 | 已审查 | 2021-09-14 04:06 | 2021-09-24 21:10 |
| GHSA-MWGJ-7X7J-6966 CVE-2021-24040 | Deserialization of Untrusted Data in ParlAI | 中危 | PyPIparlai | 已审查 | 2021-09-14 04:06 | 2021-09-14 03:29 |
| GHSA-GH8J-2PGF-X458 CVE-2021-40839 | Infinite Loop in rencode | 高危 | PyPIrencode | 已审查 | 2021-09-14 04:05 | 2024-10-27 02:35 |
| GHSA-M87F-9FVV-2MGG CVE-2021-39207 | Deserialization of Untrusted Data in parlai | 中危 | PyPIparlai | 已审查 | 2021-09-14 04:05 | 2024-10-10 05:00 |
| GHSA-4HPQ-RJCX-7VJ9 CVE-2021-23435 | Clearance Gem Open Redirect Vulnerability | 高危 | RubyGemsclearance | 已审查 | 2021-09-14 04:05 | 2023-08-26 04:56 |
| GHSA-Q897-9JXF-JG9R CVE-2021-37579 | Security check skip in Apache Dubbo | 严重 | Mavenorg.apache.dubbo:dubbo | 已审查 | 2021-09-11 01:56 | 2021-09-21 04:18 |
| GHSA-P5W8-WQHJ-9HHF CVE-2021-32839 | StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) | 高危 | PyPIsqlparse | 已审查 | 2021-09-11 01:56 | 2025-11-05 00:35 |
| GHSA-QVM7-23CJ-437V CVE-2021-36161 | Remote Code Execution in Apache Dubbo | 严重 | Mavenorg.apache.dubbo:dubbo | 已审查 | 2021-09-11 01:54 | 2021-09-21 04:15 |
| GHSA-CFC2-WJCM-C8FM CVE-2021-39206 | Incorrect Authorization with specially crafted requests | 高危 | Gogithub.com/pomerium/pomerium | 已审查 | 2021-09-11 01:54 | 2021-09-11 00:40 |
| GHSA-5WJF-62HW-Q78R CVE-2021-39204 | Excessive CPU usage | 高危 | Gogithub.com/pomerium/pomerium | 已审查 | 2021-09-11 01:54 | 2021-09-11 00:33 |
| GHSA-GJCG-VRXG-XMGV CVE-2021-39162 | Incorrect handling of H2 GOAWAY + SETTINGS frames | 高危 | Gogithub.com/pomerium/pomerium | 已审查 | 2021-09-11 01:54 | 2021-09-11 00:32 |
| GHSA-9VJP-V76F-G363 CVE-2021-37137 | SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way | 高危 | Mavenio.netty:netty+2 | 已审查 | 2021-09-10 01:11 | 2022-02-09 04:35 |