检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5PH6-QQ5X-7JWC CVE-2021-32783 | ExternalName Services can be used to gain access to Envoy's admin interface | 高危 | Gogithub.com/projectcontour/contour | 已审查 | 2021-08-31 01:22 | 2021-08-31 00:53 |
| GHSA-26RR-V2J2-25FH CVE-2021-32758 | Layout XML Arbitrary Code Fix |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
Packagistopenmage/magento-lts |
| 已审查 |
| 2021-08-31 01:20 |
| 2021-08-31 00:42 |
| GHSA-XM9F-VXMX-4M58 CVE-2021-32759 | Data Flow Sanitation Issue Fix | 高危 | Packagistopenmage/magento-lts | 已审查 | 2021-08-31 01:20 | 2021-08-31 00:42 |
| GHSA-M6H2-JX9V-58W6 CVE-2021-35936 | Missing Authorization in Apache Airflow | 中危 | PyPIapache-airflow | 已审查 | 2021-08-31 00:25 | 2024-09-12 03:51 |
| GHSA-HF6P-4RV2-9QRP CVE-2021-23423 | Path Traversal in bikshed | 中危 | PyPIbikeshed | 已审查 | 2021-08-31 00:25 | 2024-09-05 05:13 |
| GHSA-87CJ-PX37-RC3X CVE-2021-23422 | OS Command Injection in bikeshed | 高危 | PyPIbikeshed | 已审查 | 2021-08-31 00:25 | 2024-09-05 05:12 |
| GHSA-F2RP-J8HV-G5GX CVE-2021-38713 | Cross-site scripting in imgURL | 中危 | Packagisthelloxz/imgurl | 已审查 | 2021-08-31 00:25 | 2021-08-27 00:24 |
| GHSA-4Q2R-QXP6-H5J6 CVE-2020-18705 | Improper Restriction of XML External Entity Reference in Quokka | 严重 | PyPIquokka | 已审查 | 2021-08-31 00:25 | 2024-10-17 05:33 |
| GHSA-V3CG-H3F6-2242 CVE-2021-32827 | Injection in MockServer | 中危 | Mavenorg.mock-server:mockserver | 已审查 | 2021-08-31 00:24 | 2022-02-09 05:01 |
| GHSA-98HV-QFF3-8793 CVE-2020-18704 | Unrestricted Upload of File with Dangerous Type in django-widgy | 严重 | PyPIdjango-widgy | 已审查 | 2021-08-31 00:24 | 2024-09-17 06:06 |
| GHSA-3XG5-6C3J-VP8X CVE-2020-18703 | Improper Restriction of XML External Entity Reference in Quokka | 严重 | PyPIquokka | 已审查 | 2021-08-31 00:23 | 2024-10-17 05:28 |
| GHSA-5M69-3CHG-6F8M CVE-2020-18702 | Cross Site Scripting (XSS) in Quokka | 中危 | PyPIquokka | 已审查 | 2021-08-31 00:23 | 2024-10-25 05:55 |
| GHSA-CPV8-6XGR-RMF6 CVE-2021-25955 | Dolibarr Cross-site Scripting vulnerability | 严重 | Packagistdolibarr/dolibarr | 已审查 | 2021-08-31 00:22 | 2022-08-11 07:57 |
| GHSA-6GVC-4JVJ-PWQ4 | Duplicate Advisory: Use after free in libpulse-binding 已撤回 | 中危 | crates.iolibpulse-binding | 已审查 | 2021-08-31 00:22 | 2026-01-23 06:35 |
| GHSA-F8PV-X7H8-687V CVE-2020-19709 | Cross-site scripting in feehicms | 中危 | Packagistfeehi/feehicms | 已审查 | 2021-08-31 00:22 | 2021-09-03 02:50 |
| GHSA-R6G8-JMJ9-G945 CVE-2021-3734 | Improper Restriction of Rendered UI Layers or Frames in yourls | 中危 | Packagistyourls/yourls | 已审查 | 2021-08-31 00:22 | 2021-08-27 20:54 |
| GHSA-HGJR-632X-QPP3 CVE-2021-39136 | Cross-site scripting vulnerability in file upload | 高危 | Packagistbaserproject/basercms | 已审查 | 2021-08-31 00:18 | 2021-08-26 23:08 |
| GHSA-MQ5P-2MCR-M52J CVE-2021-39160 | Code injection in nbgitpuller | 高危 | PyPInbgitpuller | 已审查 | 2021-08-31 00:17 | 2024-10-04 05:28 |
| GHSA-9JJR-QQFP-PPWX CVE-2021-39159 | remote code execution via git repo provider | 严重 | PyPIbinderhub | 已审查 | 2021-08-31 00:16 | 2024-09-14 02:05 |
| GHSA-HW7R-QRHP-5PFF | Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20 | 中危 | Mavencom.vaadin:vaadin-bom | 已审查 | 2021-08-31 00:16 | 2021-08-25 23:42 |
| GHSA-QCC4-3RXF-GF4M CVE-2021-33605 | Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20 | 中危 | Mavencom.vaadin:vaadin-checkbox-flow | 已审查 | 2021-08-31 00:16 | 2021-09-04 04:35 |
| GHSA-HQXW-MM44-GC4R CVE-2021-39156 | Istio Fragments in Path May Lead to Authorization Policy Bypass | 高危 | Goistio.io/istio | 已审查 | 2021-08-31 00:16 | 2022-08-16 04:04 |
| GHSA-7774-7VR3-CC8J CVE-2021-39155 | Authorization Policy Bypass Due to Case Insensitive Host Comparison | 高危 | Goistio.io/istio | 已审查 | 2021-08-31 00:15 | 2021-12-13 21:09 |
| GHSA-9856-9GG9-QCMQ CVE-2021-39137 | Ethereum Contains Consensus Flaw During Block Processing | 中危 | Gogithub.com/ethereum/go-ethereum | 已审查 | 2021-08-31 00:15 | 2025-01-30 22:37 |
| GHSA-54GP-QFF8-946C CVE-2021-37709 | Insecure direct object reference of log files of the Import/Export feature | 中危 | Packagistshopware/core+1 | 已审查 | 2021-08-31 00:14 | 2021-08-27 03:36 |