UNKNOWN
11 записей с упоминанием · 1 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2025-11149Эксплойта нет | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.CWE-400 | Высокая7,5 | — | 0,5 % | 30 сент. 2025 г. |
61На этой неделе | CVE-2023-3460Proof of concept | Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalationultimatemember · ultimate member · CWE-269 | Критическая9,8 | — | 72,3 % | 4 июл. 2023 г. |
31Наблюдать | CVE-2022-25857Эксплойта нет | Denial of Service (DoS)snakeyaml project · snakeyaml · CWE-776 | Высокая7,5 | — | 2,7 % | 30 авг. 2022 г. |
45В плане | CVE-2022-25845Proof of concept | Deserialization of Untrusted Dataalibaba · fastjson · CWE-502 | Критическая9,8 | — | 18,7 % | 10 июн. 2022 г. |
40В плане | CVE-2022-23812Proof of concept | This affects the package node-ipc from 10.1.1 and before 10.1.3.node-ipc project · node-ipc | Критическая9,8 | — | 4,3 % | 16 мар. 2022 г. |
24Наблюдать | CVE-2021-23495Эксплойта нет | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.karma project · karma · CWE-601 | Средняя6,1 | — | 0,9 % | 25 февр. 2022 г. |
31Наблюдать | CVE-2021-23567Эксплойта нет | Denial of Service (DoS)colors.js project · colors.js · CWE-835 | Высокая7,5 | — | 1,7 % | 14 янв. 2022 г. |
31Наблюдать | CVE-2021-23446Эксплойта нет | Regular Expression Denial of Service (ReDoS)handsontable · handsontable · CWE-1333 | Высокая7,5 | — | 3,0 % | 29 сент. 2021 г. |
39Наблюдать | CVE-2021-23418Эксплойта нет | XML External Entity (XXE) Injectionglances project · glances · CWE-611 | Критическая9,8 | — | 1,6 % | 29 июл. 2021 г. |
41В плане | CVE-2021-23330Эксплойта нет | All versions of package launchpad are vulnerable to Command Injection via stop.bitovi · launchpad · CWE-78 | Критическая9,8 | — | 5,2 % | 1 февр. 2021 г. |
31Наблюдать | CVE-2020-7816Эксплойта нет | A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker thmtalk · daoffice · CWE-125 | Высокая7,8 | — | 1,4 % | 30 июн. 2020 г. |
- CVE-2025-1114930Наблюдать
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %30 сент. 2025 г.
- CVE-2023-346061На этой неделе
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
КритическаяCVSS 9,8Proof of conceptEPSS 72 %ultimatemember · ultimate member4 июл. 2023 г.
- CVE-2022-2585731Наблюдать
Denial of Service (DoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %snakeyaml project · snakeyaml30 авг. 2022 г.
- CVE-2022-2584545В плане
Deserialization of Untrusted Data
КритическаяCVSS 9,8Proof of conceptEPSS 19 %alibaba · fastjson10 июн. 2022 г.
- CVE-2022-2381240В плане
This affects the package node-ipc from 10.1.1 and before 10.1.3.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %node-ipc project · node-ipc16 мар. 2022 г.
- CVE-2021-2349524Наблюдать
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %karma project · karma25 февр. 2022 г.
- CVE-2021-2356731Наблюдать
Denial of Service (DoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %colors.js project · colors.js14 янв. 2022 г.
- CVE-2021-2344631Наблюдать
Regular Expression Denial of Service (ReDoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %handsontable · handsontable29 сент. 2021 г.
- CVE-2021-2341839Наблюдать
XML External Entity (XXE) Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %glances project · glances29 июл. 2021 г.
- CVE-2021-2333041В плане
All versions of package launchpad are vulnerable to Command Injection via stop.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %bitovi · launchpad1 февр. 2021 г.
- CVE-2020-781631Наблюдать
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker t
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hmtalk · daoffice30 июн. 2020 г.