检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-M94C-37G6-CJHC CVE-2021-37695 | Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. | 高危 | npmckeditor4 | 已审查 | 2021-08-24 03:42 | 2022-02-09 05:01 |
| GHSA-CFCV-Q4QQ-2PH4 | CKEditor 4 vulnerabilities in versions <4.16.1 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Packagistpimcore/pimcore |
| 已审查 |
| 2021-08-24 03:42 |
| 2021-10-09 05:19 |
| GHSA-23R4-5MXP-C7G5 CVE-2021-39138 | parse-server new anonymous user session acts as if it's created with password | 中危 | npmparse-server | 已审查 | 2021-08-24 03:41 | 2022-08-16 04:04 |
| GHSA-PRQF-XR2J-XF65 | Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client` | 低危 | Gogithub.com/argoproj/argo-workflows/v3 | 已审查 | 2021-08-24 03:41 | 2021-08-24 01:05 |
| GHSA-6C73-2V8X-QPVM | Argo Server TLS requests could be forged by attacker with network access | 中危 | Gogithub.com/argoproj/argo-workflows/v3 | 已审查 | 2021-08-24 03:41 | 2021-08-24 01:02 |
| GHSA-HQ5M-MQMX-FW6M CVE-2021-37627 | Privilege escalation via form generator | 高危 | Packagistcontao/contao+1 | 已审查 | 2021-08-24 03:41 | 2024-04-23 02:40 |
| GHSA-R6MV-PPJC-4HGR CVE-2021-37626 | PHP file inclusion via insert tags | 中危 | Packagistcontao/contao+1 | 已审查 | 2021-08-24 03:41 | 2024-04-23 02:42 |
| GHSA-7889-RM5J-HPGG CVE-2021-32809 | Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality | 中危 | npmckeditor4 | 已审查 | 2021-08-24 03:40 | 2022-02-09 05:01 |
| GHSA-6226-H7FF-CH6C CVE-2021-32808 | Widget feature vulnerability allowing to execute JavaScript code using undo functionality | 高危 | npmckeditor4 | 已审查 | 2021-08-24 03:40 | 2022-02-09 05:01 |
| GHSA-HWVQ-6GJX-J797 CVE-2021-32798 | Special Element Injection in notebook | 高危 | PyPInotebook | 已审查 | 2021-08-24 03:40 | 2024-10-02 05:17 |
| GHSA-4952-P58Q-6CRX CVE-2021-32797 | JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form> | 中危 | PyPIjupyterlab+1 | 已审查 | 2021-08-24 03:40 | 2024-11-19 00:26 |
| GHSA-C5C9-8C6M-727V CVE-2021-32768 | Cross-Site Scripting via Rich-Text Content | 中危 | Packagisttypo3/cms+1 | 已审查 | 2021-08-19 23:53 | 2024-02-08 02:51 |
| GHSA-Q5VH-6WHW-X745 CVE-2021-37705 | Improper Authorization and Origin Validation Error in OneFuzz | 严重 | PyPIonefuzz | 已审查 | 2021-08-14 04:16 | 2024-10-08 00:44 |
| GHSA-6XX3-RG99-GC3P CVE-2020-15522 | Timing based private key exposure in Bouncy Castle | 中危 | MavenBouncyCastle+8 | 已审查 | 2021-08-13 23:22 | 2025-07-18 06:05 |
| GHSA-3GP6-HHFW-4GQX CVE-2010-3300 | Padding oracle attacks | 中危 | Mavenorg.owasp.esapi:esapi | 已审查 | 2021-08-13 23:22 | 2021-06-29 03:05 |
| GHSA-2C25-XFPQ-8W9R CVE-2021-33348 | Cross-site scripting in jfinal | 中危 | Mavencom.jfinal:jfinal | 已审查 | 2021-08-13 23:22 | 2021-07-02 05:48 |
| GHSA-7QFM-6M33-RGG9 | XML External Entity Reference | 高危 | Mavencom.epam.reportportal:service-api | 已审查 | 2021-08-13 23:21 | 2021-06-29 03:08 |
| GHSA-793H-6F7R-6QVM CVE-2021-26920 | Druid ingestion system Authenticated users can read data from other sources than intended | 中危 | Mavenorg.apache.druid:druid-core | 已审查 | 2021-08-13 23:21 | 2023-09-26 21:12 |
| GHSA-PHWJ-86VX-CFJC CVE-2021-33192 | Cross-site scripting in Apache Jena Fuseki | 中危 | Mavenorg.apache.jena:jena-fuseki | 已审查 | 2021-08-13 23:21 | 2021-07-09 09:55 |
| GHSA-36QH-35CM-5W2W CVE-2021-30640 | Authentication Bypass by Alternate Name in Apache Tomcat | 中危 | Mavenorg.apache.tomcat:tomcat | 已审查 | 2021-08-13 23:21 | 2022-02-09 05:08 |
| GHSA-4VWW-MC66-62M6 CVE-2021-33037 | HTTP Request Smuggling in Apache Tomcat | 中危 | Mavenorg.apache.tomcat:tomcat | 已审查 | 2021-08-13 23:21 | 2024-03-12 02:00 |
| GHSA-44QP-QHFV-C7F6 CVE-2021-30639 | Improper Handling of Exceptional Conditions in Apache Tomcat | 高危 | Mavenorg.apache.tomcat:tomcat | 已审查 | 2021-08-13 23:21 | 2022-02-09 05:20 |
| GHSA-GPFJ-4J6G-C4W9 CVE-2021-37700 | Clipboard-based DOM-XSS | 中危 | npm@github/paste-markdown | 已审查 | 2021-08-13 04:42 | 2021-08-31 07:16 |
| GHSA-VXF5-WXWP-M7G9 CVE-2021-37699 | Open Redirect in Next.js | 中危 | npmnext | 已审查 | 2021-08-12 22:51 | 2022-04-29 04:32 |
| GHSA-435P-F82X-MXWM CVE-2021-38305 | Command injection in Yamale | 高危 | PyPIyamale | 已审查 | 2021-08-11 23:19 | 2024-11-20 02:25 |