qs project kayıtları
qs project üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-24999Kavram kanıtı | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicatqs project · qs · CWE-1321 | Yüksek7,5 | — | %15,6 | 26 Kas 2022 |
31İzleyin | CVE-2017-1000048İstismar yok | the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS.qs project · qs · CWE-20 | Yüksek7,5 | — | %2,4 | 17 Tem 2017 |
30İzleyin | CVE-2014-10064İstismar yok | The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply neqs project · qs · CWE-400 | Yüksek7,5 | — | %1,3 | 31 May 2018 |
25İzleyin | CVE-2026-2391İstismar yok | qs's arrayLimit bypass in comma parsing allows denial of serviceqs project · qs · CWE-20 | Orta6,3 | — | %0,5 | 12 Şub 2026 |
25İzleyin | CVE-2025-15284İstismar yok | arrayLimit bypass in bracket notation allows DoS via memory exhaustionqs project · qs · CWE-20 | Orta6,3 | — | %0,5 | 29 Ara 2025 |
- CVE-2022-2499935İzleyin
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express applicat
YüksekCVSS 7,5Kavram kanıtıEPSS %16qs project · qs26 Kas 2022
- CVE-2017-100004831İzleyin
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS.
YüksekCVSS 7,5İstismar yokEPSS %2qs project · qs17 Tem 2017
- CVE-2014-1006430İzleyin
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply ne
YüksekCVSS 7,5İstismar yokEPSS %1qs project · qs31 May 2018
- CVE-2026-239125İzleyin
qs's arrayLimit bypass in comma parsing allows denial of service
OrtaCVSS 6,3İstismar yokEPSS %1qs project · qs12 Şub 2026
- CVE-2025-1528425İzleyin
arrayLimit bypass in bracket notation allows DoS via memory exhaustion
OrtaCVSS 6,3İstismar yokEPSS %0qs project · qs29 Ara 2025