Skip to content
Noroxi

nuxtjs records

2 published records for vendor nuxtjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 22

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

2 records
  • @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    nuxtjs · \@nuxt\/devalueJul 11, 2019

  • nefly-ipx subject to Server-Side Request Forgery and Stored Cross-Site Scripting via Cache Poisoning and Improper Host Validation

    MediumCVSS 5.4No exploitEPSS 0%

    nuxtjs · netlify-ipxSep 23, 2022