sailsjs records
5 published records for vendor sailsjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 60%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-20 Improper Input Validation1
- CWE-248 Uncaught Exception1
- CWE-284 Improper Access Control1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-27262No exploit | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted sailsjs · skipper · CWE-434 | Critical9.8 | — | 2.1% | Apr 12, 2022 |
40Plan | CVE-2021-44908No exploit | SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().sailsjs · sails · CWE-1321 | Critical9.8 | — | 1.8% | Mar 17, 2022 |
31Monitor | CVE-2018-21036No exploit | Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hoosailsjs · sails · CWE-20 | High7.5 | — | 1.8% | Jul 21, 2020 |
30Monitor | CVE-2023-38504No exploit | Sails DoS vulnerability for apps with sockets enabledsailsjs · sails · CWE-248 | High7.5 | — | 0.9% | Jul 27, 2023 |
17Monitor | CVE-2016-10549No exploit | Sails is an MVC style framework for building realtime web applications.sailsjs · sails · CWE-284 | Medium4.4 | — | 0.6% | May 31, 2018 |
- CVE-2022-2726240Plan
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted
CriticalCVSS 9.8No exploitEPSS 2%sailsjs · skipperApr 12, 2022
- CVE-2021-4490840Plan
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
CriticalCVSS 9.8No exploitEPSS 2%sailsjs · sailsMar 17, 2022
- CVE-2018-2103631Monitor
Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hoo
HighCVSS 7.5No exploitEPSS 2%sailsjs · sailsJul 21, 2020
- CVE-2023-3850430Monitor
Sails DoS vulnerability for apps with sockets enabled
HighCVSS 7.5No exploitEPSS 1%sailsjs · sailsJul 27, 2023
- CVE-2016-1054917Monitor
Sails is an MVC style framework for building realtime web applications.
MediumCVSS 4.4No exploitEPSS 1%sailsjs · sailsMay 31, 2018