safe-eval project kayıtları
safe-eval project üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-265 Privilege Issues1
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-16088Kavram kanıtı | The safe-eval module describes itself as a safer version of eval.safe-eval project · safe-eval · CWE-610 | Kritik10,0 | — | %3,5 | 6 Haz 2018 |
41Planlayın | CVE-2023-26122İstismar yok | All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization.safe-eval project · safe-eval · CWE-265 | Kritik10,0 | — | %2,1 | 11 Nis 2023 |
40Planlayın | CVE-2023-26121İstismar yok | All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its psafe-eval project · safe-eval · CWE-1321 | Kritik10,0 | — | %1,1 | 11 Nis 2023 |
39İzleyin | CVE-2020-7710İstismar yok | This affects all versions of package safe-eval.safe-eval project · safe-eval · CWE-94 | Kritik9,8 | — | %1,4 | 21 Ağu 2020 |
39İzleyin | CVE-2022-25904İstismar yok | All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.psafe-eval project · safe-eval · CWE-1321 | Kritik9,8 | — | %0,9 | 20 Ara 2022 |
- CVE-2017-1608841Planlayın
The safe-eval module describes itself as a safer version of eval.
KritikCVSS 10,0Kavram kanıtıEPSS %3safe-eval project · safe-eval6 Haz 2018
- CVE-2023-2612241Planlayın
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization.
KritikCVSS 10,0İstismar yokEPSS %2safe-eval project · safe-eval11 Nis 2023
- CVE-2023-2612140Planlayın
All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its p
KritikCVSS 10,0İstismar yokEPSS %1safe-eval project · safe-eval11 Nis 2023
- CVE-2020-771039İzleyin
This affects all versions of package safe-eval.
KritikCVSS 9,8İstismar yokEPSS %1safe-eval project · safe-eval21 Ağu 2020
- CVE-2022-2590439İzleyin
All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.p
KritikCVSS 9,8İstismar yokEPSS %1safe-eval project · safe-eval20 Ara 2022