Skip to content
Noroxi

UNKNOWN

11 credited records · 1 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.

    HighCVSS 7.5No exploitEPSS 1%

    Sep 30, 2025

  • CVE-2023-3460
    61This week

    Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    ultimatemember · ultimate memberJul 4, 2023

  • Denial of Service (DoS)

    HighCVSS 7.5No exploitEPSS 3%

    snakeyaml project · snakeyamlAug 30, 2022

  • Deserialization of Untrusted Data

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    alibaba · fastjsonJun 10, 2022

  • This affects the package node-ipc from 10.1.1 and before 10.1.3.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    node-ipc project · node-ipcMar 16, 2022

  • The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    karma project · karmaFeb 25, 2022

  • Denial of Service (DoS)

    HighCVSS 7.5No exploitEPSS 2%

    colors.js project · colors.jsJan 14, 2022

  • Regular Expression Denial of Service (ReDoS)

    HighCVSS 7.5No exploitEPSS 3%

    handsontable · handsontableSep 29, 2021

  • XML External Entity (XXE) Injection

    CriticalCVSS 9.8No exploitEPSS 2%

    glances project · glancesJul 29, 2021

  • All versions of package launchpad are vulnerable to Command Injection via stop.

    CriticalCVSS 9.8No exploitEPSS 5%

    bitovi · launchpadFeb 1, 2021

  • CVE-2020-7816
    31Monitor

    A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker t

    HighCVSS 7.8No exploitEPSS 1%

    hmtalk · daofficeJun 30, 2020