gruntjs records
3 published records for vendor gruntjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2020-7729No exploit | Arbitrary Code Executiongruntjs · grunt · CWE-1188 | High7.1 | — | 2.3% | Sep 3, 2020 |
28Monitor | CVE-2022-1537No exploit | file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in gruntjs/gruntgruntjs · grunt · CWE-367 | High7.0 | — | 0.3% | May 10, 2022 |
22Monitor | CVE-2022-0436No exploit | Path Traversal in gruntjs/gruntgruntjs · grunt · CWE-22 | Medium5.5 | — | 0.6% | Apr 12, 2022 |
- CVE-2020-772929Monitor
Arbitrary Code Execution
HighCVSS 7.1No exploitEPSS 2%gruntjs · gruntSep 3, 2020
- CVE-2022-153728Monitor
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in gruntjs/grunt
HighCVSS 7.0No exploitEPSS 0%gruntjs · gruntMay 10, 2022
- CVE-2022-043622Monitor
Path Traversal in gruntjs/grunt
MediumCVSS 5.5No exploitEPSS 1%gruntjs · gruntApr 12, 2022