Skip to content
Noroxi

expressjs records

12 published records for vendor expressjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

12 records
  • CVE-2026-3520
    34Monitor

    Multer vulnerable to Denial of Service via uncontrolled recursion

    HighCVSS 8.7No exploitEPSS 1%

    expressjs · multerMar 4, 2026

  • CVE-2026-3304
    34Monitor

    Multer vulnerable to Denial of Service via incomplete cleanup

    HighCVSS 8.7Proof of conceptEPSS 1%

    expressjs · multerFeb 27, 2026

  • CVE-2026-2359
    34Monitor

    Multer vulnerable to Denial of Service via resource exhaustion

    HighCVSS 8.7No exploitEPSS 1%

    expressjs · multerFeb 27, 2026

  • basic-auth-connect's callback uses time unsafe string comparison

    HighCVSS 8.7No exploitEPSS 1%

    expressjs · basic-auth-connectSep 30, 2024

  • method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client does

    HighCVSS 7.5No exploitEPSS 1%

    expressjs · method-overrideJun 6, 2018

  • multer vulnerable to Denial of Service via oversized array index in field names

    HighCVSS 7.5No exploitEPSS 0%

    expressjs · multerAug 28, 2026

  • CVE-2026-5038
    30Monitor

    multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

    HighCVSS 7.5No exploitEPSS 0%

    expressjs · multerJun 15, 2026

  • CVE-2026-5079
    30Monitor

    multer vulnerable to Denial of Service via deeply nested field names

    HighCVSS 7.5No exploitEPSS 0%

    expressjs · multerJun 15, 2026

  • multer vulnerable to Denial of Service via crafted multipart field names

    HighCVSS 7.5Proof of conceptEPSS 0%

    expressjs · multerAug 28, 2026

  • multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

    HighCVSS 7.5No exploitEPSS 0%

    expressjs · multerAug 28, 2026

  • CVE-2024-9266
    18Monitor

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express.

    MediumCVSS 4.7No exploitEPSS 0%

    expressjs · expressOct 3, 2024

  • multer vulnerable to file size limit bypass via async fileFilter race condition

    LowCVSS 3.7No exploitEPSS 0%

    expressjs · multerAug 28, 2026