检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-F4HQ-453J-P95F CVE-2021-3189 | Open redirect in Slashify | 中危 | npmslashify | 已审查 | 2021-02-06 04:43 | 2022-05-27 04:40 |
| GHSA-4449-HG37-77V8 CVE-2020-28494 | Command injection in total.js |
当前筛选结果 366,391 条 · 时间按北京时间显示
npmtotal.js |
| 已审查 |
| 2021-02-06 04:43 |
| 2021-07-29 02:57 |
| GHSA-6CF8-QHQJ-VJQM CVE-2020-28495 | Prototype pollution in total.js | 高危 | npmtotal.js | 已审查 | 2021-02-06 04:43 | 2023-09-14 04:22 |
| GHSA-F5C9-X9J6-87QP CVE-2021-25912 | Prototype pollution in dotty | 严重 | npmdotty | 已审查 | 2021-02-06 04:43 | 2023-08-09 03:28 |
| GHSA-F62V-XPXF-3V68 CVE-2020-11979 | Code injection in Apache Ant | 高危 | Mavenorg.apache.ant:ant | 已审查 | 2021-02-04 03:16 | 2025-09-27 11:18 |
| GHSA-XHV5-W9C5-2R2W CVE-2021-21294 | Unbounded connection acceptance in http4s-blaze-server | 高危 | Mavenorg.http4s:http4s-blaze-server_2.12+1 | 已审查 | 2021-02-03 05:42 | 2022-10-26 04:51 |
| GHSA-XMW9-Q7X9-J5QC CVE-2021-21293 | Unbounded connection acceptance leads to file handle exhaustion | 高危 | Mavenorg.http4s:blaze-core_2.11+2 | 已审查 | 2021-02-03 05:42 | 2022-10-26 04:21 |
| GHSA-QRQM-FPV6-6R8G CVE-2021-21289 | Command Injection Vulnerability in Mechanize | 高危 | RubyGemsmechanize | 已审查 | 2021-02-03 02:50 | 2022-04-28 04:24 |
| GHSA-VV2X-VRPJ-QQPQ CVE-2021-23980 | Cross-site scripting in Bleach | 中危 | PyPIbleach | 已审查 | 2021-02-03 01:58 | 2025-03-21 02:50 |
| GHSA-X7P5-P2C9-PHVG | Unexpected database bindings | 高危 | Packagistilluminate/database+1 | 已审查 | 2021-02-02 23:47 | 2021-02-02 23:46 |
| GHSA-F92J-QF46-P6VM CVE-2021-21028 | Reflected Cross-site Scripting in ACS Commons | 高危 | Mavencom.adobe.acs:acs-aem-commons | 已审查 | 2021-02-02 23:46 | 2021-02-02 23:34 |
| GHSA-P4PJ-MG4R-X6V4 CVE-2021-21317 | Denial of Service in uap-core | 高危 | npmuap-core | 已审查 | 2021-02-02 23:46 | 2024-02-09 06:17 |
| GHSA-J6PX-JWVV-VPWQ CVE-2021-21277 | Angular Expressions - Remote Code Execution | 高危 | npmangular-expressions | 已审查 | 2021-02-01 23:01 | 2022-10-20 21:26 |
| GHSA-C497-V8PV-CH6X CVE-2021-23329 | Prototype pollution in nested-object-assign | 高危 | npmnested-object-assign | 已审查 | 2021-02-01 23:01 | 2023-08-09 03:28 |
| GHSA-HGMG-HHC8-G5WR CVE-2021-21254 | CKEditor 5 Markdown plugin Regular expression Denial of Service | 中危 | npm@ckeditor/ckeditor5-markdown-gfm | 已审查 | 2021-01-30 05:51 | 2022-08-12 02:16 |
| GHSA-3CRJ-W4F5-GWH4 CVE-2021-21316 | Processing untrusted theming resources might execute arbitrary code (ACE) | 高危 | npmless-openui5 | 已审查 | 2021-01-30 04:51 | 2021-02-17 01:35 |
| GHSA-HHW9-35P2-Q2C5 | Steam Socialite Provider v1 does not correctly validate openid server | 严重 | Packagistsocialiteproviders/steam | 已审查 | 2021-01-30 04:51 | 2021-01-30 04:39 |
| GHSA-P7V4-GM6J-CW9M CVE-2021-3142 | XSS in Mautic | 高危 | Packagistmautic/core | 已审查 | 2021-01-30 04:51 | 2021-01-30 04:31 |
| GHSA-2CWJ-8CHV-9PP9 CVE-2018-1285 | XML External Entity attack in log4net | 严重 | NuGetlog4net | 已审查 | 2021-01-30 03:47 | 2021-08-26 04:55 |
| GHSA-6C3F-P5WP-34MH CVE-2021-3190 | OS Command Injection in async-git | 严重 | npmasync-git | 已审查 | 2021-01-30 02:14 | 2022-05-03 10:56 |
| GHSA-2HW7-MXVJ-M455 CVE-2021-3223 | Path traversal in Node-RED-Dashboard | 高危 | npmnode-red-dashboard | 已审查 | 2021-01-30 02:13 | 2021-01-28 07:26 |
| GHSA-H3GG-7WX2-CQ3H CVE-2021-21283 | XSS in Flarum Sticky extension | 中危 | Packagistflarum/sticky | 已审查 | 2021-01-30 02:13 | 2021-01-27 04:41 |
| GHSA-32WX-4GXX-H48F | Users can edit the tags of any discussion | 中危 | Packagistflarum/tags | 已审查 | 2021-01-30 02:13 | 2021-01-26 11:45 |
| GHSA-VHHW-XJVF-WPRR CVE-2021-23326 | Command Injection in @graphql-tools/git-loader | 高危 | npm@graphql-tools/git-loader | 已审查 | 2021-01-30 02:13 | 2022-06-01 05:40 |
| GHSA-43HG-G44Q-474Q CVE-2021-3137 | Cross Site Scripting (XSS) in XWiki | 中危 | Mavenorg.xwiki.commons:xwiki-commons | 已审查 | 2021-01-30 02:13 | 2021-01-23 02:46 |