Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nodejs vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-7598
minimist prior to 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Substack Minimist
Opensuse Leap 15.1
8 Github repositories
6.8
CVSSv2
CVE-2014-9748
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv prior to 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows malicious users to cause a denial of service (deadlock) or possibly have unspecified other impa...
Libuv Libuv
Nodejs Node.js
6.8
CVSSv2
CVE-2019-6644
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in deb...
F5 Big-ip Local Traffic Manager
F5 Big-ip Local Traffic Manager 14.1.0
F5 Big-ip Local Traffic Manager 14.0.0
F5 Big-ip Advanced Firewall Manager 14.1.0
F5 Big-ip Advanced Firewall Manager
F5 Big-ip Advanced Firewall Manager 14.0.0
F5 Big-ip Application Acceleration Manager
F5 Big-ip Application Acceleration Manager 14.0.0
F5 Big-ip Application Acceleration Manager 14.1.0
F5 Big-ip Analytics 14.0.0
F5 Big-ip Analytics
F5 Big-ip Analytics 14.1.0
F5 Big-ip Access Policy Manager
F5 Big-ip Access Policy Manager 14.0.0
F5 Big-ip Access Policy Manager 14.1.0
F5 Big-ip Application Security Manager
F5 Big-ip Application Security Manager 14.1.0
F5 Big-ip Application Security Manager 14.0.0
F5 Big-ip Edge Gateway 14.1.0
F5 Big-ip Edge Gateway
F5 Big-ip Edge Gateway 14.0.0
F5 Big-ip Fraud Protection Service
6.8
CVSSv2
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations a...
Apple Swiftnio
Apache Traffic Server
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 19.04
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 30
Synology Skynas -
Synology Diskstation Manager 6.2
Synology Vs960hd Firmware -
Fedoraproject Fedora 29
Fedoraproject Fedora 32
Opensuse Leap 15.0
Opensuse Leap 15.1
Redhat Software Collections 1.0
Redhat Jboss Core Services 1.0
Redhat Enterprise Linux 8.0
Redhat Jboss Enterprise Application Platform 7.2.0
Redhat Quay 3.0.0
Redhat Openshift Service Mesh 1.0
Redhat Jboss Enterprise Application Platform 7.3.0
6.8
CVSSv2
CVE-2018-12120
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug po...
Nodejs Node.js
6.8
CVSSv2
CVE-2016-10618
node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Node-browser Project Node-browser
6.8
CVSSv2
CVE-2016-10578
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode prior to 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Unicode Project Unicode
6.8
CVSSv2
CVE-2015-2927
node 0.3.2 and URONode prior to 1.0.5r3 allows remote malicious users to cause a denial of service (bandwidth consumption).
Uronode Uro Node
Nodejs Node.js 0.3.2
Debian Debian Linux 8.0
Debian Debian Linux 9.0
6.8
CVSSv2
CVE-2013-4660
The JS-YAML module prior to 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote malicious users to execute arbitrary code via a crafted string that triggers an eval operation.
Js-yaml Project Js-yaml 0.2.2
Js-yaml Project Js-yaml 0.3.1
Js-yaml Project Js-yaml 1.0.0
Js-yaml Project Js-yaml 1.0.2
Js-yaml Project Js-yaml 2.0.3
Js-yaml Project Js-yaml 0.2.0
Js-yaml Project Js-yaml 0.2.1
Js-yaml Project Js-yaml 1.0.3
Js-yaml Project Js-yaml 2.0.0
Js-yaml Project Js-yaml 2.0.1
Js-yaml Project Js-yaml 2.0.2
Js-yaml Project Js-yaml 0.3.3
Js-yaml Project Js-yaml 0.3.4
Js-yaml Project Js-yaml 0.3.5
Js-yaml Project Js-yaml 0.3.6
Js-yaml Project Js-yaml 0.3.0
Js-yaml Project Js-yaml 0.3.2
Js-yaml Project Js-yaml 0.3.7
Js-yaml Project Js-yaml 1.0.1
Js-yaml Project Js-yaml
1 EDB exploit
1 Github repository
6.5
CVSSv2
CVE-2021-23280
Eaton Intelligent Power Manager (IPM) before 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an malicious user to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execut...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »