unjs kayıtları
unjs üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-184 Incomplete List of Disallowed Inputs1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-69874İstismar yok | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fiunjs · nanotar · CWE-22 | Kritik9,8 | — | %0,9 | 11 Şub 2026 |
30İzleyin | CVE-2026-35209İstismar yok | defu: Prototype pollution via `__proto__` key in defaults argumentunjs · defu · CWE-1321 | Yüksek7,5 | — | %0,5 | 6 Nis 2026 |
27İzleyin | CVE-2025-54387İstismar yok | IPX is Vulnerable to Path Traversal via Prefix Matching Bypassunjs · ipx · CWE-22 | Orta6,9 | — | %0,7 | 4 Ağu 2025 |
24İzleyin | CVE-2026-39315İstismar yok | Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()unjs · unhead · CWE-184 | Orta6,1 | — | %0,3 | 9 Nis 2026 |
24İzleyin | CVE-2026-31873İstismar yok | Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivityunjs · unhead · CWE-79 | Orta6,1 | — | %0,3 | 12 Mar 2026 |
21İzleyin | CVE-2026-31860İstismar yok | Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol checkunjs · unhead · CWE-79 | Orta5,3 | — | %0,3 | 12 Mar 2026 |
- CVE-2025-6987439İzleyin
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fi
KritikCVSS 9,8İstismar yokEPSS %1unjs · nanotar11 Şub 2026
- CVE-2026-3520930İzleyin
defu: Prototype pollution via `__proto__` key in defaults argument
YüksekCVSS 7,5İstismar yokEPSS %1unjs · defu6 Nis 2026
- CVE-2025-5438727İzleyin
IPX is Vulnerable to Path Traversal via Prefix Matching Bypass
OrtaCVSS 6,9İstismar yokEPSS %1unjs · ipx4 Ağu 2025
- CVE-2026-3931524İzleyin
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
OrtaCVSS 6,1İstismar yokEPSS %0unjs · unhead9 Nis 2026
- CVE-2026-3187324İzleyin
Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
OrtaCVSS 6,1İstismar yokEPSS %0unjs · unhead12 Mar 2026
- CVE-2026-3186021İzleyin
Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
OrtaCVSS 5,3İstismar yokEPSS %0unjs · unhead12 Mar 2026