shell-quote project kayıtları
shell-quote project üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-42740İstismar yok | The shell-quote package before 1.7.3 for Node.js allows command injection.shell-quote project · shell-quote · CWE-77 | Kritik9,8 | — | %4,2 | 21 Eki 2021 |
40Planlayın | CVE-2016-10541İstismar yok | The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell.shell-quote project · shell-quote · CWE-78 | Kritik9,8 | — | %2,2 | 31 May 2018 |
34İzleyin | CVE-2026-13311İstismar yok | shell-quote parse() is quadratic in token count, enabling denial of serviceshell-quote project · shell-quote · CWE-407 | Yüksek8,7 | — | %0,4 | 25 Haz 2026 |
- CVE-2021-4274040Planlayın
The shell-quote package before 1.7.3 for Node.js allows command injection.
KritikCVSS 9,8İstismar yokEPSS %4shell-quote project · shell-quote21 Eki 2021
- CVE-2016-1054140Planlayın
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell.
KritikCVSS 9,8İstismar yokEPSS %2shell-quote project · shell-quote31 May 2018
- CVE-2026-1331134İzleyin
shell-quote parse() is quadratic in token count, enabling denial of service
YüksekCVSS 8,7İstismar yokEPSS %0shell-quote project · shell-quote25 Haz 2026