Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typeorm typeorm vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-33171
The findOne function in TypeORM prior to 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor&...
Typeorm Typeorm
9.8
CVSSv3
CVE-2020-8158
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow malicious users to add or modify Object properties leading to further denial of service or SQL injection attacks.
Typeorm Typeorm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started