openjsf kayıtları
openjsf üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %92,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-436 Interpretation Conflict6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-25244İstismar yok | WebdriverIO has Command Injection in the BrowserStack Serviceopenjsf · webdriverio · CWE-78 | Kritik9,8 | — | %3,3 | 18 May 2026 |
35İzleyin | CVE-2022-24999Kavram kanıtı | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicatqs project · qs · CWE-1321 | Yüksek7,5 | — | %15,6 | 26 Kas 2022 |
31İzleyin | CVE-2026-10796İstismar yok | nvm executes commands from a malicious Node.js mirror's version stringsopenjsf · node version manager · CWE-78 | Yüksek7,5 | — | %5,0 | 4 Haz 2026 |
30İzleyin | CVE-2024-45590Kavram kanıtı | body-parser vulnerable to denial of service when url encoding is enabledopenjsf · body-parser · CWE-405 | Yüksek7,5 | — | %0,8 | 10 Eyl 2024 |
30İzleyin | CVE-2026-6321İstismar yok | fast-uri vulnerable to path traversal via percent-encoded dot segmentsopenjsf · fast-uri · CWE-22 | Yüksek7,5 | — | %0,8 | 4 May 2026 |
30İzleyin | CVE-2026-6322İstismar yok | fast-uri vulnerable to host confusion via percent-encoded authority delimitersopenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,7 | 5 May 2026 |
30İzleyin | CVE-2024-29900İstismar yok | @electron/packager's build process memory potentially leaked into final executableopenjsf · packager · CWE-402 | Yüksek7,5 | — | %0,6 | 29 Mar 2024 |
30İzleyin | CVE-2024-26136İstismar yok | kedi ElectronCord's Discord Token is publicopenjsf · electroncord · CWE-200 | Yüksek7,5 | — | %0,5 | 20 Şub 2024 |
30İzleyin | CVE-2026-13676İstismar yok | fast-uri vulnerable to host confusion via failed IDN canonicalizationopenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,5 | 29 Haz 2026 |
30İzleyin | CVE-2025-57349İstismar yok | The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollutiopenjsf · messageformat · CWE-1321 | Yüksek7,5 | — | %0,4 | 24 Eyl 2025 |
30İzleyin | CVE-2026-75931İstismar yok | fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative referencesopenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,4 | 24 Ağu 2026 |
30İzleyin | CVE-2026-76172İstismar yok | fast-uri vulnerable to host confusion via percent-encoded scheme normalizationopenjsf · fast-uri · CWE-177 | Yüksek7,5 | — | %0,4 | 24 Ağu 2026 |
30İzleyin | CVE-2026-84292İstismar yok | fast-uri vulnerable to authority injection via an unvalidated port in serializeopenjsf · fast-uri · CWE-116 | Yüksek7,5 | — | %0,4 | 2 Eyl 2026 |
30İzleyin | CVE-2026-84394İstismar yok | fast-uri vulnerable to host confusion via an unclosed bracket in the URI authorityopenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,4 | 3 Eyl 2026 |
30İzleyin | CVE-2026-75975İstismar yok | fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationopenjsf · fast-uri · CWE-20 | Yüksek7,5 | — | %0,4 | 24 Ağu 2026 |
30İzleyin | CVE-2026-75899İstismar yok | fast-uri vulnerable to server-side request forgery via repeated hostname percent-decodingopenjsf · fast-uri · CWE-174 | Yüksek7,5 | — | %0,4 | 24 Ağu 2026 |
30İzleyin | CVE-2026-16221İstismar yok | fast-uri vulnerable to host confusion via literal backslash authority delimiteropenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,3 | 19 Tem 2026 |
30İzleyin | CVE-2026-18446İstismar yok | fast-uri vulnerable to host confusion via backslash authority introduceropenjsf · fast-uri · CWE-436 | Yüksek7,5 | — | %0,2 | 31 Tem 2026 |
25İzleyin | CVE-2015-8856İstismar yok | Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary webopenjsf · serve-index · CWE-79 | Orta6,1 | — | %2,5 | 23 Oca 2017 |
25İzleyin | CVE-2026-41591İstismar yok | Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escapingopenjsf · marko · CWE-79 | Orta6,4 | — | %0,3 | 8 May 2026 |
24İzleyin | CVE-2014-6393İstismar yok | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 leopenjsf · express · CWE-79 | Orta6,1 | — | %1,1 | 9 Ağu 2017 |
24İzleyin | CVE-2024-29041İstismar yok | Express.js Open Redirect in malformed URLsopenjsf · express · CWE-601 | Orta6,1 | — | %0,8 | 25 Mar 2024 |
23İzleyin | CVE-2026-12590İstismar yok | body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementopenjsf · body-parser · CWE-770 | Orta5,9 | — | %0,4 | 9 Tem 2026 |
22İzleyin | CVE-2025-50537İstismar yok | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.jsopenjsf · eslint · CWE-674 | Orta5,5 | — | %0,2 | 26 Oca 2026 |
21İzleyin | CVE-2020-4051İstismar yok | XSS in Dijit Editor's LinkDialog pluginopenjsf · dijit · CWE-79 | Orta5,4 | — | %1,2 | 15 Haz 2020 |
- CVE-2026-2524440Planlayın
WebdriverIO has Command Injection in the BrowserStack Service
KritikCVSS 9,8İstismar yokEPSS %3openjsf · webdriverio18 May 2026
- CVE-2022-2499935İzleyin
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicat
YüksekCVSS 7,5Kavram kanıtıEPSS %16qs project · qs26 Kas 2022
- CVE-2026-1079631İzleyin
nvm executes commands from a malicious Node.js mirror's version strings
YüksekCVSS 7,5İstismar yokEPSS %5openjsf · node version manager4 Haz 2026
- CVE-2024-4559030İzleyin
body-parser vulnerable to denial of service when url encoding is enabled
YüksekCVSS 7,5Kavram kanıtıEPSS %1openjsf · body-parser10 Eyl 2024
- CVE-2026-632130İzleyin
fast-uri vulnerable to path traversal via percent-encoded dot segments
YüksekCVSS 7,5İstismar yokEPSS %1openjsf · fast-uri4 May 2026
- CVE-2026-632230İzleyin
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
YüksekCVSS 7,5İstismar yokEPSS %1openjsf · fast-uri5 May 2026
- CVE-2024-2990030İzleyin
@electron/packager's build process memory potentially leaked into final executable
YüksekCVSS 7,5İstismar yokEPSS %1openjsf · packager29 Mar 2024
- CVE-2024-2613630İzleyin
kedi ElectronCord's Discord Token is public
YüksekCVSS 7,5İstismar yokEPSS %1openjsf · electroncord20 Şub 2024
- CVE-2026-1367630İzleyin
fast-uri vulnerable to host confusion via failed IDN canonicalization
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri29 Haz 2026
- CVE-2025-5734930İzleyin
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype polluti
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · messageformat24 Eyl 2025
- CVE-2026-7593130İzleyin
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri24 Ağu 2026
- CVE-2026-7617230İzleyin
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri24 Ağu 2026
- CVE-2026-8429230İzleyin
fast-uri vulnerable to authority injection via an unvalidated port in serialize
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri2 Eyl 2026
- CVE-2026-8439430İzleyin
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri3 Eyl 2026
- CVE-2026-7597530İzleyin
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri24 Ağu 2026
- CVE-2026-7589930İzleyin
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri24 Ağu 2026
- CVE-2026-1622130İzleyin
fast-uri vulnerable to host confusion via literal backslash authority delimiter
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri19 Tem 2026
- CVE-2026-1844630İzleyin
fast-uri vulnerable to host confusion via backslash authority introducer
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri31 Tem 2026
- CVE-2015-885625İzleyin
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web
OrtaCVSS 6,1İstismar yokEPSS %2openjsf · serve-index23 Oca 2017
- CVE-2026-4159125İzleyin
Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping
OrtaCVSS 6,4İstismar yokEPSS %0openjsf · marko8 May 2026
- CVE-2014-639324İzleyin
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 le
OrtaCVSS 6,1İstismar yokEPSS %1openjsf · express9 Ağu 2017
- CVE-2024-2904124İzleyin
Express.js Open Redirect in malformed URLs
OrtaCVSS 6,1İstismar yokEPSS %1openjsf · express25 Mar 2024
- CVE-2026-1259023İzleyin
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
OrtaCVSS 5,9İstismar yokEPSS %0openjsf · body-parser9 Tem 2026
- CVE-2025-5053722İzleyin
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js
OrtaCVSS 5,5İstismar yokEPSS %0openjsf · eslint26 Oca 2026
- CVE-2020-405121İzleyin
XSS in Dijit Editor's LinkDialog plugin
OrtaCVSS 5,4İstismar yokEPSS %1openjsf · dijit15 Haz 2020