expressjs records
12 published records for vendor expressjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption4
- CWE-459 Incomplete Cleanup2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-674 Uncontrolled Recursion1
- CWE-208 Observable Timing Discrepancy1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-3520No exploit | Multer vulnerable to Denial of Service via uncontrolled recursionexpressjs · multer · CWE-674 | High8.7 | — | 0.9% | Mar 4, 2026 |
34Monitor | CVE-2026-3304Proof of concept | Multer vulnerable to Denial of Service via incomplete cleanupexpressjs · multer · CWE-459 | High8.7 | — | 0.9% | Feb 27, 2026 |
34Monitor | CVE-2026-2359No exploit | Multer vulnerable to Denial of Service via resource exhaustionexpressjs · multer · CWE-772 | High8.7 | — | 0.7% | Feb 27, 2026 |
34Monitor | CVE-2024-47178No exploit | basic-auth-connect's callback uses time unsafe string comparisonexpressjs · basic-auth-connect · CWE-208 | High8.7 | — | 0.5% | Sep 30, 2024 |
30Monitor | CVE-2017-16136No exploit | method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesexpressjs · method-override · CWE-400 | High7.5 | — | 1.2% | Jun 6, 2018 |
30Monitor | CVE-2026-82333No exploit | multer vulnerable to Denial of Service via oversized array index in field namesexpressjs · multer · CWE-400 | High7.5 | — | 0.5% | Aug 28, 2026 |
30Monitor | CVE-2026-5038No exploit | multer vulnerable to Denial of Service via incomplete cleanup of aborted uploadsexpressjs · multer · CWE-459 | High7.5 | — | 0.5% | Jun 15, 2026 |
30Monitor | CVE-2026-5079No exploit | multer vulnerable to Denial of Service via deeply nested field namesexpressjs · multer · CWE-400 | High7.5 | — | 0.5% | Jun 15, 2026 |
30Monitor | CVE-2026-77078Proof of concept | multer vulnerable to Denial of Service via crafted multipart field namesexpressjs · multer · CWE-248 | High7.5 | — | 0.5% | Aug 28, 2026 |
30Monitor | CVE-2026-77037No exploit | multer vulnerable to Denial of Service via file descriptor leak on aborted uploadsexpressjs · multer · CWE-400 | High7.5 | — | 0.3% | Aug 28, 2026 |
18Monitor | CVE-2024-9266No exploit | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express.expressjs · express · CWE-601 | Medium4.7 | — | 0.5% | Oct 3, 2024 |
14Monitor | CVE-2026-77063No exploit | multer vulnerable to file size limit bypass via async fileFilter race conditionexpressjs · multer · CWE-362 | Low3.7 | — | 0.2% | Aug 28, 2026 |
- CVE-2026-352034Monitor
Multer vulnerable to Denial of Service via uncontrolled recursion
HighCVSS 8.7No exploitEPSS 1%expressjs · multerMar 4, 2026
- CVE-2026-330434Monitor
Multer vulnerable to Denial of Service via incomplete cleanup
HighCVSS 8.7Proof of conceptEPSS 1%expressjs · multerFeb 27, 2026
- CVE-2026-235934Monitor
Multer vulnerable to Denial of Service via resource exhaustion
HighCVSS 8.7No exploitEPSS 1%expressjs · multerFeb 27, 2026
- CVE-2024-4717834Monitor
basic-auth-connect's callback uses time unsafe string comparison
HighCVSS 8.7No exploitEPSS 1%expressjs · basic-auth-connectSep 30, 2024
- CVE-2017-1613630Monitor
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client does
HighCVSS 7.5No exploitEPSS 1%expressjs · method-overrideJun 6, 2018
- CVE-2026-8233330Monitor
multer vulnerable to Denial of Service via oversized array index in field names
HighCVSS 7.5No exploitEPSS 0%expressjs · multerAug 28, 2026
- CVE-2026-503830Monitor
multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
HighCVSS 7.5No exploitEPSS 0%expressjs · multerJun 15, 2026
- CVE-2026-507930Monitor
multer vulnerable to Denial of Service via deeply nested field names
HighCVSS 7.5No exploitEPSS 0%expressjs · multerJun 15, 2026
- CVE-2026-7707830Monitor
multer vulnerable to Denial of Service via crafted multipart field names
HighCVSS 7.5Proof of conceptEPSS 0%expressjs · multerAug 28, 2026
- CVE-2026-7703730Monitor
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
HighCVSS 7.5No exploitEPSS 0%expressjs · multerAug 28, 2026
- CVE-2024-926618Monitor
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express.
MediumCVSS 4.7No exploitEPSS 0%expressjs · expressOct 3, 2024
- CVE-2026-7706314Monitor
multer vulnerable to file size limit bypass via async fileFilter race condition
LowCVSS 3.7No exploitEPSS 0%expressjs · multerAug 28, 2026