nestjs kayıtları
nestjs üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-674 Uncontrolled Recursion1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2025-54782Kavram kanıtı | @nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developersnestjs · devtools-integration · CWE-77 | Kritik9,4 | — | %51,3 | 1 Ağu 2025 |
34İzleyin | CVE-2026-33011İstismar yok | Nest Fastify HEAD Request Middleware Bypassnestjs · nest · CWE-670 | Yüksek8,7 | — | %0,5 | 20 Mar 2026 |
32İzleyin | CVE-2026-2293İstismar yok | NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypassnestjs · nest · CWE-863 | Yüksek8,2 | — | %0,7 | 27 Şub 2026 |
30İzleyin | CVE-2026-40879İstismar yok | Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)nestjs · nest · CWE-674 | Yüksek7,5 | — | %0,5 | 21 Nis 2026 |
27İzleyin | CVE-2025-69211İstismar yok | Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)nestjs · nest · CWE-367 | Orta6,9 | — | %0,4 | 29 Ara 2025 |
25İzleyin | CVE-2026-35515İstismar yok | @nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')nestjs · nest · CWE-74 | Orta6,3 | — | %0,3 | 7 Nis 2026 |
22İzleyin | CVE-2024-29409İstismar yok | File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.nestjs · nest · CWE-94 | Orta5,5 | — | %0,3 | 14 Mar 2025 |
21İzleyin | CVE-2023-26108İstismar yok | Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe.nestjs · nest · CWE-200 | Orta5,3 | — | %0,7 | 6 Mar 2023 |
- CVE-2025-5478252Planlayın
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
KritikCVSS 9,4Kavram kanıtıEPSS %51nestjs · devtools-integration1 Ağu 2025
- CVE-2026-3301134İzleyin
Nest Fastify HEAD Request Middleware Bypass
YüksekCVSS 8,7İstismar yokEPSS %0nestjs · nest20 Mar 2026
- CVE-2026-229332İzleyin
NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
YüksekCVSS 8,2İstismar yokEPSS %1nestjs · nest27 Şub 2026
- CVE-2026-4087930İzleyin
Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)
YüksekCVSS 7,5İstismar yokEPSS %0nestjs · nest21 Nis 2026
- CVE-2025-6921127İzleyin
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
OrtaCVSS 6,9İstismar yokEPSS %0nestjs · nest29 Ara 2025
- CVE-2026-3551525İzleyin
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')
OrtaCVSS 6,3İstismar yokEPSS %0nestjs · nest7 Nis 2026
- CVE-2024-2940922İzleyin
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
OrtaCVSS 5,5İstismar yokEPSS %0nestjs · nest14 Mar 2025
- CVE-2023-2610821İzleyin
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe.
OrtaCVSS 5,3İstismar yokEPSS %1nestjs · nest6 Mar 2023