UNKNOWN
11 kredili kayıt · son 12 ayda 1 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2025-11149İstismar yok | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.CWE-400 | Yüksek7,5 | — | %0,5 | 30 Eyl 2025 |
61Bu hafta | CVE-2023-3460Kavram kanıtı | Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalationultimatemember · ultimate member · CWE-269 | Kritik9,8 | — | %72,3 | 4 Tem 2023 |
31İzleyin | CVE-2022-25857İstismar yok | Denial of Service (DoS)snakeyaml project · snakeyaml · CWE-776 | Yüksek7,5 | — | %2,7 | 30 Ağu 2022 |
45Planlayın | CVE-2022-25845Kavram kanıtı | Deserialization of Untrusted Dataalibaba · fastjson · CWE-502 | Kritik9,8 | — | %18,7 | 10 Haz 2022 |
40Planlayın | CVE-2022-23812Kavram kanıtı | This affects the package node-ipc from 10.1.1 and before 10.1.3.node-ipc project · node-ipc | Kritik9,8 | — | %4,3 | 16 Mar 2022 |
24İzleyin | CVE-2021-23495İstismar yok | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.karma project · karma · CWE-601 | Orta6,1 | — | %0,9 | 25 Şub 2022 |
31İzleyin | CVE-2021-23567İstismar yok | Denial of Service (DoS)colors.js project · colors.js · CWE-835 | Yüksek7,5 | — | %1,7 | 14 Oca 2022 |
31İzleyin | CVE-2021-23446İstismar yok | Regular Expression Denial of Service (ReDoS)handsontable · handsontable · CWE-1333 | Yüksek7,5 | — | %3,0 | 29 Eyl 2021 |
39İzleyin | CVE-2021-23418İstismar yok | XML External Entity (XXE) Injectionglances project · glances · CWE-611 | Kritik9,8 | — | %1,6 | 29 Tem 2021 |
41Planlayın | CVE-2021-23330İstismar yok | All versions of package launchpad are vulnerable to Command Injection via stop.bitovi · launchpad · CWE-78 | Kritik9,8 | — | %5,2 | 1 Şub 2021 |
31İzleyin | CVE-2020-7816İstismar yok | A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker thmtalk · daoffice · CWE-125 | Yüksek7,8 | — | %1,4 | 30 Haz 2020 |
- CVE-2025-1114930İzleyin
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static.
YüksekCVSS 7,5İstismar yokEPSS %130 Eyl 2025
- CVE-2023-346061Bu hafta
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
KritikCVSS 9,8Kavram kanıtıEPSS %72ultimatemember · ultimate member4 Tem 2023
- CVE-2022-2585731İzleyin
Denial of Service (DoS)
YüksekCVSS 7,5İstismar yokEPSS %3snakeyaml project · snakeyaml30 Ağu 2022
- CVE-2022-2584545Planlayın
Deserialization of Untrusted Data
KritikCVSS 9,8Kavram kanıtıEPSS %19alibaba · fastjson10 Haz 2022
- CVE-2022-2381240Planlayın
This affects the package node-ipc from 10.1.1 and before 10.1.3.
KritikCVSS 9,8Kavram kanıtıEPSS %4node-ipc project · node-ipc16 Mar 2022
- CVE-2021-2349524İzleyin
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
OrtaCVSS 6,1İstismar yokEPSS %1karma project · karma25 Şub 2022
- CVE-2021-2356731İzleyin
Denial of Service (DoS)
YüksekCVSS 7,5İstismar yokEPSS %2colors.js project · colors.js14 Oca 2022
- CVE-2021-2344631İzleyin
Regular Expression Denial of Service (ReDoS)
YüksekCVSS 7,5İstismar yokEPSS %3handsontable · handsontable29 Eyl 2021
- CVE-2021-2341839İzleyin
XML External Entity (XXE) Injection
KritikCVSS 9,8İstismar yokEPSS %2glances project · glances29 Tem 2021
- CVE-2021-2333041Planlayın
All versions of package launchpad are vulnerable to Command Injection via stop.
KritikCVSS 9,8İstismar yokEPSS %5bitovi · launchpad1 Şub 2021
- CVE-2020-781631İzleyin
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker t
YüksekCVSS 7,8İstismar yokEPSS %1hmtalk · daoffice30 Haz 2020