UNKNOWN
11 credited records · 1 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2025-11149No exploit | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.CWE-400 | High7.5 | — | 0.5% | Sep 30, 2025 |
61This week | CVE-2023-3460Proof of concept | Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalationultimatemember · ultimate member · CWE-269 | Critical9.8 | — | 72.3% | Jul 4, 2023 |
31Monitor | CVE-2022-25857No exploit | Denial of Service (DoS)snakeyaml project · snakeyaml · CWE-776 | High7.5 | — | 2.7% | Aug 30, 2022 |
45Plan | CVE-2022-25845Proof of concept | Deserialization of Untrusted Dataalibaba · fastjson · CWE-502 | Critical9.8 | — | 18.7% | Jun 10, 2022 |
40Plan | CVE-2022-23812Proof of concept | This affects the package node-ipc from 10.1.1 and before 10.1.3.node-ipc project · node-ipc | Critical9.8 | — | 4.3% | Mar 16, 2022 |
24Monitor | CVE-2021-23495No exploit | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.karma project · karma · CWE-601 | Medium6.1 | — | 0.9% | Feb 25, 2022 |
31Monitor | CVE-2021-23567No exploit | Denial of Service (DoS)colors.js project · colors.js · CWE-835 | High7.5 | — | 1.7% | Jan 14, 2022 |
31Monitor | CVE-2021-23446No exploit | Regular Expression Denial of Service (ReDoS)handsontable · handsontable · CWE-1333 | High7.5 | — | 3.0% | Sep 29, 2021 |
39Monitor | CVE-2021-23418No exploit | XML External Entity (XXE) Injectionglances project · glances · CWE-611 | Critical9.8 | — | 1.6% | Jul 29, 2021 |
41Plan | CVE-2021-23330No exploit | All versions of package launchpad are vulnerable to Command Injection via stop.bitovi · launchpad · CWE-78 | Critical9.8 | — | 5.2% | Feb 1, 2021 |
31Monitor | CVE-2020-7816No exploit | A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker thmtalk · daoffice · CWE-125 | High7.8 | — | 1.4% | Jun 30, 2020 |
- CVE-2025-1114930Monitor
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.
HighCVSS 7.5No exploitEPSS 1%Sep 30, 2025
- CVE-2023-346061This week
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
CriticalCVSS 9.8Proof of conceptEPSS 72%ultimatemember · ultimate memberJul 4, 2023
- CVE-2022-2585731Monitor
Denial of Service (DoS)
HighCVSS 7.5No exploitEPSS 3%snakeyaml project · snakeyamlAug 30, 2022
- CVE-2022-2584545Plan
Deserialization of Untrusted Data
CriticalCVSS 9.8Proof of conceptEPSS 19%alibaba · fastjsonJun 10, 2022
- CVE-2022-2381240Plan
This affects the package node-ipc from 10.1.1 and before 10.1.3.
CriticalCVSS 9.8Proof of conceptEPSS 4%node-ipc project · node-ipcMar 16, 2022
- CVE-2021-2349524Monitor
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
MediumCVSS 6.1No exploitEPSS 1%karma project · karmaFeb 25, 2022
- CVE-2021-2356731Monitor
Denial of Service (DoS)
HighCVSS 7.5No exploitEPSS 2%colors.js project · colors.jsJan 14, 2022
- CVE-2021-2344631Monitor
Regular Expression Denial of Service (ReDoS)
HighCVSS 7.5No exploitEPSS 3%handsontable · handsontableSep 29, 2021
- CVE-2021-2341839Monitor
XML External Entity (XXE) Injection
CriticalCVSS 9.8No exploitEPSS 2%glances project · glancesJul 29, 2021
- CVE-2021-2333041Plan
All versions of package launchpad are vulnerable to Command Injection via stop.
CriticalCVSS 9.8No exploitEPSS 5%bitovi · launchpadFeb 1, 2021
- CVE-2020-781631Monitor
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker t
HighCVSS 7.8No exploitEPSS 1%hmtalk · daofficeJun 30, 2020