Записи openjsf
28 опубликованных записей вендора openjsf.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 92,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-436 Interpretation Conflict6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2026-25244Эксплойта нет | WebdriverIO has Command Injection in the BrowserStack Serviceopenjsf · webdriverio · CWE-78 | Критическая9,8 | — | 3,3 % | 18 мая 2026 г. |
35Наблюдать | CVE-2022-24999Proof of concept | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicatqs project · qs · CWE-1321 | Высокая7,5 | — | 15,6 % | 26 нояб. 2022 г. |
31Наблюдать | CVE-2026-10796Эксплойта нет | nvm executes commands from a malicious Node.js mirror's version stringsopenjsf · node version manager · CWE-78 | Высокая7,5 | — | 5,0 % | 4 июн. 2026 г. |
30Наблюдать | CVE-2024-45590Proof of concept | body-parser vulnerable to denial of service when url encoding is enabledopenjsf · body-parser · CWE-405 | Высокая7,5 | — | 0,8 % | 10 сент. 2024 г. |
30Наблюдать | CVE-2026-6321Эксплойта нет | fast-uri vulnerable to path traversal via percent-encoded dot segmentsopenjsf · fast-uri · CWE-22 | Высокая7,5 | — | 0,8 % | 4 мая 2026 г. |
30Наблюдать | CVE-2026-6322Эксплойта нет | fast-uri vulnerable to host confusion via percent-encoded authority delimitersopenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,7 % | 5 мая 2026 г. |
30Наблюдать | CVE-2024-29900Эксплойта нет | @electron/packager's build process memory potentially leaked into final executableopenjsf · packager · CWE-402 | Высокая7,5 | — | 0,6 % | 29 мар. 2024 г. |
30Наблюдать | CVE-2024-26136Эксплойта нет | kedi ElectronCord's Discord Token is publicopenjsf · electroncord · CWE-200 | Высокая7,5 | — | 0,5 % | 20 февр. 2024 г. |
30Наблюдать | CVE-2026-13676Эксплойта нет | fast-uri vulnerable to host confusion via failed IDN canonicalizationopenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,5 % | 29 июн. 2026 г. |
30Наблюдать | CVE-2025-57349Эксплойта нет | The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollutiopenjsf · messageformat · CWE-1321 | Высокая7,5 | — | 0,4 % | 24 сент. 2025 г. |
30Наблюдать | CVE-2026-75931Эксплойта нет | fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative referencesopenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,4 % | 24 авг. 2026 г. |
30Наблюдать | CVE-2026-84394Эксплойта нет | fast-uri vulnerable to host confusion via an unclosed bracket in the URI authorityopenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,4 % | 3 сент. 2026 г. |
30Наблюдать | CVE-2026-16221Эксплойта нет | fast-uri vulnerable to host confusion via literal backslash authority delimiteropenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,3 % | 19 июл. 2026 г. |
30Наблюдать | CVE-2026-84292Эксплойта нет | fast-uri vulnerable to authority injection via an unvalidated port in serializeopenjsf · fast-uri · CWE-116 | Высокая7,5 | — | 0,2 % | 2 сент. 2026 г. |
30Наблюдать | CVE-2026-76172Эксплойта нет | fast-uri vulnerable to host confusion via percent-encoded scheme normalizationopenjsf · fast-uri · CWE-177 | Высокая7,5 | — | 0,2 % | 24 авг. 2026 г. |
30Наблюдать | CVE-2026-18446Эксплойта нет | fast-uri vulnerable to host confusion via backslash authority introduceropenjsf · fast-uri · CWE-436 | Высокая7,5 | — | 0,2 % | 31 июл. 2026 г. |
30Наблюдать | CVE-2026-75975Эксплойта нет | fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationopenjsf · fast-uri · CWE-20 | Высокая7,5 | — | 0,2 % | 24 авг. 2026 г. |
30Наблюдать | CVE-2026-75899Эксплойта нет | fast-uri vulnerable to server-side request forgery via repeated hostname percent-decodingopenjsf · fast-uri · CWE-174 | Высокая7,5 | — | 0,2 % | 24 авг. 2026 г. |
25Наблюдать | CVE-2015-8856Эксплойта нет | Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary webopenjsf · serve-index · CWE-79 | Средняя6,1 | — | 2,5 % | 23 янв. 2017 г. |
25Наблюдать | CVE-2026-41591Эксплойта нет | Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escapingopenjsf · marko · CWE-79 | Средняя6,4 | — | 0,3 % | 8 мая 2026 г. |
24Наблюдать | CVE-2014-6393Эксплойта нет | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 leopenjsf · express · CWE-79 | Средняя6,1 | — | 1,1 % | 9 авг. 2017 г. |
24Наблюдать | CVE-2024-29041Эксплойта нет | Express.js Open Redirect in malformed URLsopenjsf · express · CWE-601 | Средняя6,1 | — | 0,8 % | 25 мар. 2024 г. |
23Наблюдать | CVE-2026-12590Эксплойта нет | body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementopenjsf · body-parser · CWE-770 | Средняя5,9 | — | 0,4 % | 9 июл. 2026 г. |
22Наблюдать | CVE-2025-50537Эксплойта нет | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.jsopenjsf · eslint · CWE-674 | Средняя5,5 | — | 0,2 % | 26 янв. 2026 г. |
21Наблюдать | CVE-2020-4051Эксплойта нет | XSS in Dijit Editor's LinkDialog pluginopenjsf · dijit · CWE-79 | Средняя5,4 | — | 1,2 % | 15 июн. 2020 г. |
- CVE-2026-2524440В плане
WebdriverIO has Command Injection in the BrowserStack Service
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openjsf · webdriverio18 мая 2026 г.
- CVE-2022-2499935Наблюдать
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicat
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %qs project · qs26 нояб. 2022 г.
- CVE-2026-1079631Наблюдать
nvm executes commands from a malicious Node.js mirror's version strings
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openjsf · node version manager4 июн. 2026 г.
- CVE-2024-4559030Наблюдать
body-parser vulnerable to denial of service when url encoding is enabled
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %openjsf · body-parser10 сент. 2024 г.
- CVE-2026-632130Наблюдать
fast-uri vulnerable to path traversal via percent-encoded dot segments
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openjsf · fast-uri4 мая 2026 г.
- CVE-2026-632230Наблюдать
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openjsf · fast-uri5 мая 2026 г.
- CVE-2024-2990030Наблюдать
@electron/packager's build process memory potentially leaked into final executable
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openjsf · packager29 мар. 2024 г.
- CVE-2024-2613630Наблюдать
kedi ElectronCord's Discord Token is public
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openjsf · electroncord20 февр. 2024 г.
- CVE-2026-1367630Наблюдать
fast-uri vulnerable to host confusion via failed IDN canonicalization
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri29 июн. 2026 г.
- CVE-2025-5734930Наблюдать
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype polluti
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · messageformat24 сент. 2025 г.
- CVE-2026-7593130Наблюдать
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri24 авг. 2026 г.
- CVE-2026-8439430Наблюдать
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri3 сент. 2026 г.
- CVE-2026-1622130Наблюдать
fast-uri vulnerable to host confusion via literal backslash authority delimiter
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri19 июл. 2026 г.
- CVE-2026-8429230Наблюдать
fast-uri vulnerable to authority injection via an unvalidated port in serialize
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri2 сент. 2026 г.
- CVE-2026-7617230Наблюдать
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri24 авг. 2026 г.
- CVE-2026-1844630Наблюдать
fast-uri vulnerable to host confusion via backslash authority introducer
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri31 июл. 2026 г.
- CVE-2026-7597530Наблюдать
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri24 авг. 2026 г.
- CVE-2026-7589930Наблюдать
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri24 авг. 2026 г.
- CVE-2015-885625Наблюдать
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web
СредняяCVSS 6,1Эксплойта нетEPSS 2 %openjsf · serve-index23 янв. 2017 г.
- CVE-2026-4159125Наблюдать
Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping
СредняяCVSS 6,4Эксплойта нетEPSS 0 %openjsf · marko8 мая 2026 г.
- CVE-2014-639324Наблюдать
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 le
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openjsf · express9 авг. 2017 г.
- CVE-2024-2904124Наблюдать
Express.js Open Redirect in malformed URLs
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openjsf · express25 мар. 2024 г.
- CVE-2026-1259023Наблюдать
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
СредняяCVSS 5,9Эксплойта нетEPSS 0 %openjsf · body-parser9 июл. 2026 г.
- CVE-2025-5053722Наблюдать
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js
СредняяCVSS 5,5Эксплойта нетEPSS 0 %openjsf · eslint26 янв. 2026 г.
- CVE-2020-405121Наблюдать
XSS in Dijit Editor's LinkDialog plugin
СредняяCVSS 5,4Эксплойта нетEPSS 1 %openjsf · dijit15 июн. 2020 г.