nodeca kayıtları
nodeca üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %16,7
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-407 Inefficient Algorithmic Complexity4
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2013-4660Silahlaştırılmış | The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attanodeca · js-yaml · CWE-20 | Orta6,8 | — | %17,3 | 28 Haz 2013 |
30İzleyin | CVE-2026-59868İstismar yok | js-yaml: YAML merge-key chains can force quadratic CPU consumptionnodeca · js-yaml · CWE-407 | Yüksek7,5 | — | %0,6 | 8 Tem 2026 |
30İzleyin | CVE-2026-59870İstismar yok | js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsingnodeca · js-yaml · CWE-407 | Yüksek7,5 | — | %0,6 | 8 Tem 2026 |
30İzleyin | CVE-2026-59869İstismar yok | js-yaml: YAML merge-key chains can force quadratic CPU consumptionnodeca · js-yaml · CWE-407 | Yüksek7,5 | — | %0,6 | 8 Tem 2026 |
21İzleyin | CVE-2026-53550İstismar yok | js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliasesnodeca · js-yaml · CWE-407 | Orta5,3 | — | %0,4 | 22 Haz 2026 |
21İzleyin | CVE-2025-64718İstismar yok | js-yaml has prototype pollution in merge (<<)nodeca · js-yaml · CWE-1321 | Orta5,3 | — | %0,4 | 13 Kas 2025 |
- CVE-2013-466032İzleyin
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote atta
OrtaCVSS 6,8SilahlaştırılmışEPSS %17nodeca · js-yaml28 Haz 2013
- CVE-2026-5986830İzleyin
js-yaml: YAML merge-key chains can force quadratic CPU consumption
YüksekCVSS 7,5İstismar yokEPSS %1nodeca · js-yaml8 Tem 2026
- CVE-2026-5987030İzleyin
js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
YüksekCVSS 7,5İstismar yokEPSS %1nodeca · js-yaml8 Tem 2026
- CVE-2026-5986930İzleyin
js-yaml: YAML merge-key chains can force quadratic CPU consumption
YüksekCVSS 7,5İstismar yokEPSS %1nodeca · js-yaml8 Tem 2026
- CVE-2026-5355021İzleyin
js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases
OrtaCVSS 5,3İstismar yokEPSS %0nodeca · js-yaml22 Haz 2026
- CVE-2025-6471821İzleyin
js-yaml has prototype pollution in merge (<<)
OrtaCVSS 5,3İstismar yokEPSS %0nodeca · js-yaml13 Kas 2025