sequelizejs kayıtları
sequelizejs üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-790 Improper Filtering of Special Elements1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-10550İstismar yok | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,9 | 31 May 2018 |
40Planlayın | CVE-2016-10554İstismar yok | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,9 | 31 May 2018 |
39İzleyin | CVE-2019-10752İstismar yok | Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escapsequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,5 | 17 Eki 2019 |
39İzleyin | CVE-2023-25813Kavram kanıtı | SQL Injection via replacements in sequelizesequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,4 | 22 Şub 2023 |
39İzleyin | CVE-2019-10748İstismar yok | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped sequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,3 | 29 Eki 2019 |
39İzleyin | CVE-2016-10553İstismar yok | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,3 | 31 May 2018 |
39İzleyin | CVE-2019-10749İstismar yok | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Posequelizejs · sequelize · CWE-89 | Kritik9,8 | — | %1,2 | 29 Eki 2019 |
39İzleyin | CVE-2023-22578İstismar yok | Sequalize - Default support for “raw attributes” when using parenthesessequelizejs · sequelize · CWE-790 | Kritik9,8 | — | %0,8 | 16 Şub 2023 |
35İzleyin | CVE-2023-22579İstismar yok | Sequalize - Unsafe fall-through in getWhereConditionssequelizejs · sequelize · CWE-843 | Yüksek8,8 | — | %0,8 | 16 Şub 2023 |
31İzleyin | CVE-2019-11069İstismar yok | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.sequelizejs · sequelize · CWE-20 | Yüksek7,5 | — | %1,8 | 10 Nis 2019 |
30İzleyin | CVE-2016-10556İstismar yok | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server isequelizejs · sequelize · CWE-89 | Yüksek7,5 | — | %1,3 | 29 May 2018 |
30İzleyin | CVE-2023-22580İstismar yok | Sequalize - Bad query filtering leading to SQL errorssequelizejs · sequelize · CWE-200 | Yüksek7,5 | — | %0,6 | 16 Şub 2023 |
30İzleyin | CVE-2026-30951Kavram kanıtı | Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Typesequelizejs · sequelize · CWE-89 | Yüksek7,5 | — | %0,5 | 10 Mar 2026 |
28İzleyin | CVE-2023-6293İstismar yok | Prototype Pollution in robinbuschmann/sequelize-typescriptsequelizejs · sequelize-typescript · CWE-1321 | Yüksek7,1 | — | %0,6 | 24 Kas 2023 |
- CVE-2016-1055040Planlayın
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
KritikCVSS 9,8İstismar yokEPSS %2sequelizejs · sequelize31 May 2018
- CVE-2016-1055440Planlayın
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
KritikCVSS 9,8İstismar yokEPSS %2sequelizejs · sequelize31 May 2018
- CVE-2019-1075239İzleyin
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escap
KritikCVSS 9,8İstismar yokEPSS %1sequelizejs · sequelize17 Eki 2019
- CVE-2023-2581339İzleyin
SQL Injection via replacements in sequelize
KritikCVSS 9,8Kavram kanıtıEPSS %1sequelizejs · sequelize22 Şub 2023
- CVE-2019-1074839İzleyin
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped
KritikCVSS 9,8İstismar yokEPSS %1sequelizejs · sequelize29 Eki 2019
- CVE-2016-1055339İzleyin
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
KritikCVSS 9,8İstismar yokEPSS %1sequelizejs · sequelize31 May 2018
- CVE-2019-1074939İzleyin
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Po
KritikCVSS 9,8İstismar yokEPSS %1sequelizejs · sequelize29 Eki 2019
- CVE-2023-2257839İzleyin
Sequalize - Default support for “raw attributes” when using parentheses
KritikCVSS 9,8İstismar yokEPSS %1sequelizejs · sequelize16 Şub 2023
- CVE-2023-2257935İzleyin
Sequalize - Unsafe fall-through in getWhereConditions
YüksekCVSS 8,8İstismar yokEPSS %1sequelizejs · sequelize16 Şub 2023
- CVE-2019-1106931İzleyin
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
YüksekCVSS 7,5İstismar yokEPSS %2sequelizejs · sequelize10 Nis 2019
- CVE-2016-1055630İzleyin
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server i
YüksekCVSS 7,5İstismar yokEPSS %1sequelizejs · sequelize29 May 2018
- CVE-2023-2258030İzleyin
Sequalize - Bad query filtering leading to SQL errors
YüksekCVSS 7,5İstismar yokEPSS %1sequelizejs · sequelize16 Şub 2023
- CVE-2026-3095130İzleyin
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
YüksekCVSS 7,5Kavram kanıtıEPSS %0sequelizejs · sequelize10 Mar 2026
- CVE-2023-629328İzleyin
Prototype Pollution in robinbuschmann/sequelize-typescript
YüksekCVSS 7,1İstismar yokEPSS %1sequelizejs · sequelize-typescript24 Kas 2023