umbraengineering records
2 published records for vendor umbraengineering.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-16460No exploit | A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.umbraengineering · ps · CWE-77 | Critical9.8 | — | 2.9% | Sep 7, 2018 |
39Monitor | CVE-2018-3751No exploit | The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object wheumbraengineering · merge-recursive · CWE-20 | Critical9.8 | — | 1.4% | Jul 3, 2018 |
- CVE-2018-1646040Plan
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
CriticalCVSS 9.8No exploitEPSS 3%umbraengineering · psSep 7, 2018
- CVE-2018-375139Monitor
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object whe
CriticalCVSS 9.8No exploitEPSS 1%umbraengineering · merge-recursiveJul 3, 2018